Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2024-21508: mysql2 library can let attackers execute code
CVE-2024-21508 · published 14 days ago
Summary
The mysql2 code library used in Node.js applications can be tricked into running malicious commands. This could let an attacker take control of the system that uses the library. Update mysql2 to the latest version that includes the fix.
What to do
- Update sidorares mysql2 to version 3.9.4.
- Update rootio @rootio/mysql2 to version 3.9.2-root.io.1.
- Update rootio @rootio/mysql2 to version 3.9.2-root.io.2.
- Update rootio @rootio/mysql2 to version 2.3.3-root.io.4.
- Update GitHub Actions mysql2 to version 3.9.2-aikido.1.
- Update GitHub Actions mysql2 to version 3.9.2-aikido.2.
- Update GitHub Actions mysql2 to version 2.3.3-aikido.4.
- Update mysql2 to version 3.7.1-aikido.3.
- Update rootio @rootio/mysql2 to version 3.7.1-root.io.3.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | sidorares | mysql2 |
< 3.9.4 Fix: upgrade to 3.9.4
|
| Root:npm | rootio | @rootio/mysql2 |
< 3.9.2-root.io.1 < 3.9.2-root.io.2 < 2.3.3-root.io.4 < 3.7.1-root.io.3 Fix: upgrade to 3.9.2-root.io.1
|
| Root:npm | GitHub Actions | mysql2 |
< 3.9.2-aikido.1 < 3.9.2-aikido.2 < 2.3.3-aikido.4 Fix: upgrade to 3.9.2-aikido.1
|
| Root:npm | – | mysql2 |
< 3.7.1-aikido.3 Fix: upgrade to 3.7.1-aikido.3
|
Original advisory text
CVE-2024-21508 in mysql2 - Patched by Root
Root has patched CVE-2024-21508 in the mysql2 package for Root:npm. Multiple fixed versions available.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-21508
- https://github.com/sidorares/node-mysql2/pull/2572
- https://github.com/sidorares/node-mysql2/commit/74abf9ef94d76114d9a09415e28b4965...
- https://blog.slonser.info/posts/mysql2-attacker-configuration
- https://github.com/sidorares/node-mysql2/blob/1609b5393516d72a4ae47196837317fbe7...
- https://github.com/sidorares/node-mysql2/releases/tag/v3.9.4
- https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6591085
- https://github.com/advisories/GHSA-fpw7-j2hg-69v5
- https://blog.slonser.info/posts/mysql2-attacker-configuration/
Severity
9.8
Critical
CVSS 3.1: 9.8 (GHSA)
Exploitation
EPSS 3%
Type
CWE-94Code Injection
Timeline
Published11 Sep 2026
Updated22 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta