logo

Database

Prototype Pollution In mysql2

Description

mysql2 vulnerable to Prototype Poisoning Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through parserFn in text_parser.js and binary_parser.js.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-R8WEC – Vulnerability | Fluid Attacks Database