{"id":"CVE-2024-21509","aliases":["GHSA-49j4-86m8-q2jw"],"url":"https://o3.security/vulnerability/CVE-2024-21509","summary":"mysql2 vulnerable to Prototype Poisoning","details":"Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through parserFn in text_parser.js and binary_parser.js.","published":"2024-04-10T05:00:00.795Z","modified":"2026-08-12T03:51:19.743516816Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"mysql2","fixedVersion":"3.9.4"}],"fix":{"url":"https://github.com/sidorares/node-mysql2/commit/4a964a3910a4b8de008696c554ab1b492e9b4691","label":"sidorares/node-mysql2@4a964a3"},"references":[{"type":"WEB","url":"https://github.com/sidorares/node-mysql2/blob/fd3d117da82cc5c5fa5a3701d7b33ca77691bc61/lib/parsers/text_parser.js%23L134"},{"type":"WEB","url":"https://github.com/sidorares/node-mysql2/releases/tag/v3.9.4"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6591084"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21509.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21509"},{"type":"FIX","url":"https://github.com/sidorares/node-mysql2/commit/4a964a3910a4b8de008696c554ab1b492e9b4691"},{"type":"FIX","url":"https://github.com/sidorares/node-mysql2/pull/2574"},{"type":"ARTICLE","url":"https://blog.slonser.info/posts/mysql2-attacker-configuration/"},{"type":"WEB","url":"https://blog.slonser.info/posts/mysql2-attacker-configuration"},{"type":"PACKAGE","url":"https://github.com/sidorares/node-mysql2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:19.743516816Z"}}