VDB
Sign up
MEDIUM6.5

GHSA-49j4-86m8-q2jw

mysql2 vulnerable to Prototype Poisoning

Quick fix

GHSA-49j4-86m8-q2jw — mysql2: upgrade to the fixed version with the command below.

npm install mysql2@3.9.4

Details

Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through `parserFn` in `text_parser.js` and `binary_parser.js`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mysql2
Introduced in: 0Fixed in: 3.9.4
Fixnpm install mysql2@3.9.4

References