PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107384 MariaDB Corporation CVE debrief

MariaDB Connector/Node.js versions 3.2.0 through 3.2.5, 3.3.0 through 3.3.4, 3.4.0 through 3.4.7, and 3.5.0-rc.0 through 3.5.4 are vulnerable to SQL injection attacks when permitSetMultiParamEntries is enabled. An attacker-controlled key containing a backtick can close the quoted identifier and cause the remainder of the key to be interpreted as SQL, potentially leading to unauthorized data access or modification. Defenders should prioritize verifying exposure in Node.js applications using these vulnerable versions, especially where permitSetMultiParamEntries is enabled, and update to fixed versions 3.2.5, 3.3.4, 3.4.7, or 3.5.4.

Vendor
MariaDB Corporation
Product
MariaDB Connector/Node.js
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-09
Advisory published
2026-10-08
Advisory updated
2026-10-09

Who should care

Defenders of Node.js applications using MariaDB Connector/Node.js, especially those enabling permitSetMultiParamEntries, should assess exposure and prioritize updates to fixed versions.

Why it matters

Defenders should prioritize verifying exposure in Node.js applications using MariaDB Connector/Node.js versions 3.2.0 through 3.2.5, 3.3.0 through 3.3.4, 3.4.0 through 3.4.7, and 3.5.0-rc.0 through 3.5.4, especially where permitSetMultiParamEntries is enabled, due to potential for SQL injection and unauthorized data access or modification.

  • Potential for unauthorized data exposure and modification
  • Possible injection of arbitrary SQL queries
  • Elevation of privileges through database user's permissions
  • Need for verification of affected versions and configurations

Technical summary

MariaDB Connector/Node.js versions 3.2.0 through 3.2.5, 3.3.0 through 3.3.4, 3.4.0 through 3.4.7, and 3.5.0-rc.0 through 3.5.4 are vulnerable to SQL injection when permitSetMultiParamEntries is enabled. An attacker-controlled key containing a backtick can close the quoted identifier and cause the remainder of the key to be interpreted as SQL. This can lead to unauthorized data access or modification, and defenders should prioritize verifying exposure in Node.js applications using these vulnerable versions, especially where permitSetMultiParamEntries is enabled.

Defensive priority

Defenders should prioritize verifying exposure in Node.js applications using MariaDB Connector/Node.js versions 3.2.0 through 3.2.5, 3.3.0 through 3.3.4, 3.4.0 through 3.4.7, and 3.5.0-rc.0 through 3.5.4, especially where permitSetMultiParamEntries is enabled.

Recommended defensive actions

  • Verify Node.js applications using MariaDB Connector/Node.js versions 3.2.0 through 3.2.5, 3.3.0 through 3.3.4, 3.4.0 through 3.4.7, and 3.5.0-rc.0 through 3.5.4 for exposure, especially where permitSetMultiParamEntries
  • Update to fixed versions 3.2.5, 3.3.4, 3.4.7, or 3.5.4
  • Review application code for use of permitSetMultiParamEntries and object key expansion
  • Monitor database activity for suspicious SQL queries
  • Perform a thorough review of the application code to identify potential vulnerabilities
  • Implement compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions and retest remediated assets to ensure the vulnerability is fully resolved

Evidence notes

The CVE record and source item provide details on the SQL injection vulnerability in MariaDB Connector/Node.js. The issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4. Evidence limits suggest that defenders verify affected versions and configurations, and review application code for use of permitSetMultiParamEntries and object key expansion.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107384 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107384

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107384 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107384

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • MariaDB Connector/Node.js: SQL injection through object keys in SET expansion (permitSetMultiPar

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107384.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-v6pj-gxxw-phfw

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/144b8f4ef29539a9fb4b75d972b9dcdac4088b4e

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/6743b2f4a89b074268b44c650170767f35e1fb5d

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/8eb450972ff0f3826d7d45c071a42240798bc826

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/b9b04ec82a60b2caf2b0c038259ca9aff5d7014a

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://hackerone.com/reports/3889198

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.