{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mariadb-connector/node.js--3.2.5--3.3.0--3.3.4--3.4.0--3.4.7--3.5.0-rc.0--3.5.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mariadb:mariadb_connector_nodejs:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-107385"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MariaDB Connector/Node.js (\u003c 3.2.5, \u003e= 3.3.0 \u003c 3.3.4, \u003e= 3.4.0 \u003c 3.4.7, \u003e= 3.5.0-rc.0 \u003c 3.5.4)","MariaDB Connector/Node.js (\u003e= 3.2.0, \u003c 3.2.5, \u003e= 3.3.0, \u003c 3.3.4, \u003e= 3.4.0, \u003c 3.4.7, \u003e= 3.5.0-rc.0, \u003c 3.5.4)"],"_cs_severities":["high"],"_cs_tags":["sql-injection","nodejs","database-security"],"_cs_type":"advisory","_cs_vendors":["MariaDB"],"content_html":"\u003cp\u003eMariaDB Connector/Node.js (CVE-2026-107385) contains a vulnerability in its parameter-escaping logic for the text protocol. When a database session is configured with the NO_BACKSLASH_ESCAPES SQL mode, the connector fails to recognize the mode, continuing to escape quotes with backslashes rather than doubling them. This behavior results in a mismatch where the escaped value prematurely closes the SQL string literal. An attacker capable of influencing query parameters can escape the string context and inject arbitrary SQL commands. The vulnerability affects all standard text-protocol entry points, including the Connection.escape() method. While the vulnerability requires the specific NO_BACKSLASH_ESCAPES mode to be active, this can be set server-wide, via connector session initialization, or through individual application queries. The binary prepared-statement protocol (execute/batch) remains unaffected.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a web application using the vulnerable MariaDB Connector/Node.js driver.\u003c/li\u003e\n\u003cli\u003eAttacker verifies the target database session has the NO_BACKSLASH_ESCAPES SQL mode enabled.\u003c/li\u003e\n\u003cli\u003eAttacker identifies an application input field that passes data to a SQL query using the connector's text protocol (e.g., query() method).\u003c/li\u003e\n\u003cli\u003eAttacker submits a crafted payload containing a single quote, which the connector improperly escapes with a backslash.\u003c/li\u003e\n\u003cli\u003eThe backslash, treated as a literal character in NO_BACKSLASH_ESCAPES mode, fails to prevent the quote from terminating the string literal.\u003c/li\u003e\n\u003cli\u003eThe injected SQL following the terminated string literal is parsed and executed by the MariaDB server.\u003c/li\u003e\n\u003cli\u003eAttacker achieves unauthorized data exfiltration, modification, or deletion based on the application's database user permissions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthenticated or authenticated SQL injection, leading to unauthorized read, modification, or deletion of database contents. The impact is equivalent to the privileges granted to the database user account used by the application, which may expose sensitive organizational data or compromise application integrity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize upgrading the MariaDB Connector/Node.js package to a version that addresses CVE-2026-107385 (\u0026gt;= 3.2.5, \u0026gt;= 3.3.4, \u0026gt;= 3.4.7, or \u0026gt;= 3.5.4). If immediate patching is not possible, enforce the use of the binary protocol (execute() or batch()) for all database interactions, as these methods are not affected by this flaw. Audit application-level configurations to determine if NO_BACKSLASH_ESCAPES mode is explicitly enabled within session variables or initialization scripts.\u003c/p\u003e\n","date_modified":"2026-10-08T19:43:34Z","date_published":"2026-10-08T19:43:22Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mariadb-node-sqli/","summary":"The MariaDB Connector/Node.js fails to properly escape input parameters for the text protocol when NO_BACKSLASH_ESCAPES mode is enabled, allowing attackers to perform SQL injection via standard placeholder APIs.","title":"SQL Injection in MariaDB Connector/Node.js","url":"https://feed.craftedsignal.io/briefs/2026-10-mariadb-node-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - MariaDB Connector/Node.js (\u003c 3.2.5, \u003e= 3.3.0 \u003c 3.3.4, \u003e= 3.4.0 \u003c 3.4.7, \u003e= 3.5.0-Rc.0 \u003c 3.5.4)","version":"https://jsonfeed.org/version/1.1"}