{"id":"CVE-2024-21512","aliases":["GHSA-pmh2-wpjm-fj45"],"url":"https://o3.security/vulnerability/CVE-2024-21512","summary":"mysql2 vulnerable to Prototype Pollution","details":"Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.","published":"2024-05-29T05:00:01.515Z","modified":"2026-07-15T01:48:57.276051066Z","cvss":{"score":8.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L/E:P"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"mysql2","fixedVersion":"3.9.8"}],"fix":{"url":"https://github.com/sidorares/node-mysql2/commit/efe3db527a2c94a63c2d14045baba8dfefe922bc","label":"sidorares/node-mysql2@efe3db5"},"references":[{"type":"WEB","url":"https://gist.github.com/domdomi3/e9f0f9b9b1ed6bfbbc0bea87c5ca1e4a"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-7176010"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6861580"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21512.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21512"},{"type":"FIX","url":"https://github.com/sidorares/node-mysql2/commit/efe3db527a2c94a63c2d14045baba8dfefe922bc"},{"type":"FIX","url":"https://github.com/sidorares/node-mysql2/pull/2702"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:57.276051066Z"}}