{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "3.2.5"
              },
              {
                "introduced": "3.3.0"
              },
              {
                "fixed": "3.3.4"
              },
              {
                "introduced": "3.4.0"
              },
              {
                "fixed": "3.4.7"
              },
              {
                "introduced": "3.5.0-rc.0"
              },
              {
                "fixed": "3.5.4"
              }
            ],
            "source": [
              "AFFECTED_FIELD",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "introduced": "b65aca10b77f5ede83f16a8edd0537b2ef12a16f"
            },
            {
              "introduced": "24a58245cba201da91f41f7f96f8dd165d31c6c7"
            },
            {
              "introduced": "07d0183bbcf61a9cd9a5b39a74a67d676e83b4d8"
            },
            {
              "fixed": "d7c1aed221af4bf811e7d13f3e29c2f7484bb0e0"
            },
            {
              "fixed": "ee9b296894d0c9bcc0e0f6b9ac9316f498eecec4"
            },
            {
              "fixed": "67c931b7407fc4e460aab020e7cb53bcb1c62e50"
            },
            {
              "fixed": "ff43a2c80ebba9e6590afd6b9cc08ac0a290892a"
            },
            {
              "fixed": "6995c8cf8e51b2ad055de63dcaa4094eebbef5ce"
            },
            {
              "fixed": "7670d90949307e735c0ae148d80b3776478a599d"
            },
            {
              "fixed": "95886df9fa0cca991e2be339caa6c3979be61553"
            },
            {
              "fixed": "e5a9d732d9574177749488336319b73074072779"
            }
          ],
          "repo": "https://github.com/mariadb-corporation/mariadb-connector-nodejs",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-r3rv-jm3r-62q2"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107385.json"
  },
  "details": "MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, text-protocol escaping always prefixes quotes with a backslash and does not honor the session's NO_BACKSLASH_ESCAPES mode, including in Connection.escape(). When that mode is enabled, the backslash is an ordinary character, so an attacker-controlled placeholder value can close the SQL string literal and inject arbitrary SQL with the application's database privileges. The vulnerable configuration may be enabled server-wide, through connector initialization options, or with an application-issued SET sql_mode; execute() and batch() use binary protocols and are not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.",
  "id": "CVE-2026-107385",
  "modified": "2026-10-10T02:30:23.122260052Z",
  "published": "2026-10-08T18:38:29.490Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5"
    },
    {
      "type": "WEB",
      "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.3.4"
    },
    {
      "type": "WEB",
      "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.4.7"
    },
    {
      "type": "WEB",
      "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4"
    },
    {
      "type": "WEB",
      "url": "https://hackerone.com/reports/3889197"
    },
    {
      "type": "WEB",
      "url": "https://jira.mariadb.org/browse/CONJS-368"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107385.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-r3rv-jm3r-62q2"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107385"
    },
    {
      "type": "FIX",
      "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/6995c8cf8e51b2ad055de63dcaa4094eebbef5ce"
    },
    {
      "type": "FIX",
      "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/7670d90949307e735c0ae148d80b3776478a599d"
    },
    {
      "type": "FIX",
      "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/95886df9fa0cca991e2be339caa6c3979be61553"
    },
    {
      "type": "FIX",
      "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/e5a9d732d9574177749488336319b73074072779"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "MariaDB Connector/Node.js: SQL injection in the text protocol when the session uses NO_BACKSLASH_ESCAPES"
}