{"id":"GHSA-pmh2-wpjm-fj45","summary":"mysql2 vulnerable to Prototype Pollution","details":"Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.","aliases":["CVE-2024-21512"],"modified":"2026-07-17T21:05:12.372942300Z","published":"2024-05-30T18:34:32Z","database_specific":{"nvd_published_at":"2024-05-29T05:16:08Z","cwe_ids":["CWE-1321"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-30T18:34:32Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21512"},{"type":"WEB","url":"https://github.com/sidorares/node-mysql2/pull/2702"},{"type":"WEB","url":"https://github.com/sidorares/node-mysql2/commit/efe3db527a2c94a63c2d14045baba8dfefe922bc"},{"type":"WEB","url":"https://gist.github.com/domdomi3/e9f0f9b9b1ed6bfbbc0bea87c5ca1e4a"},{"type":"PACKAGE","url":"https://github.com/sidorares/node-mysql2"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-7176010"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6861580"}],"affected":[{"package":{"name":"mysql2","ecosystem":"npm","purl":"pkg:npm/mysql2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.9.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-pmh2-wpjm-fj45/GHSA-pmh2-wpjm-fj45.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"}]}