Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2024-21508: mysql2 library can let attackers execute code

CVE-2024-21508 · published 14 days ago
Summary

The mysql2 code library used in Node.js applications can be tricked into running malicious commands. This could let an attacker take control of the system that uses the library. Update mysql2 to the latest version that includes the fix.

What to do
  • Update sidorares mysql2 to version 3.9.4.
  • Update rootio @rootio/mysql2 to version 3.9.2-root.io.1.
  • Update rootio @rootio/mysql2 to version 3.9.2-root.io.2.
  • Update rootio @rootio/mysql2 to version 2.3.3-root.io.4.
  • Update GitHub Actions mysql2 to version 3.9.2-aikido.1.
  • Update GitHub Actions mysql2 to version 3.9.2-aikido.2.
  • Update GitHub Actions mysql2 to version 2.3.3-aikido.4.
  • Update mysql2 to version 3.7.1-aikido.3.
  • Update rootio @rootio/mysql2 to version 3.7.1-root.io.3.
Affected software
Ecosystem VendorProductAffected versions
npm sidorares mysql2 < 3.9.4
Fix: upgrade to 3.9.4
Root:npm rootio @rootio/mysql2 < 3.9.2-root.io.1
< 3.9.2-root.io.2
< 2.3.3-root.io.4
< 3.7.1-root.io.3
Fix: upgrade to 3.9.2-root.io.1
Root:npm GitHub Actions mysql2 < 3.9.2-aikido.1
< 3.9.2-aikido.2
< 2.3.3-aikido.4
Fix: upgrade to 3.9.2-aikido.1
Root:npm – mysql2 < 3.7.1-aikido.3
Fix: upgrade to 3.7.1-aikido.3
Original advisory text
CVE-2024-21508 in mysql2 - Patched by Root
Root has patched CVE-2024-21508 in the mysql2 package for Root:npm. Multiple fixed versions available.
Severity
9.8 Critical
CVSS 3.1: 9.8 (GHSA)
Exploitation
EPSS 3%
Type
CWE-94Code Injection
Timeline
Published11 Sep 2026
Updated22 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta