Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2024-21511: mysql2 packages can let attackers run unauthorized code

CVE-2024-21511 · published 14 days ago
Summary

The mysql2 library used in several projects (sidorares/mysql2, @rootio/mysql2, GitHub Actions/mysql2, and mysql2) has a security weakness that could allow an attacker to execute code on your server. The issue has been fixed in recent releases, so update the mysql2 package to the latest version as soon as possible to keep your systems safe.

What to do
  • Update sidorares mysql2 to version 3.9.7.
  • Update rootio @rootio/mysql2 to version 3.9.7-root.io.2.
  • Update GitHub Actions mysql2 to version 3.9.7-aikido.2.
  • Update mysql2 to version 3.9.7-aikido.2.
Affected software
Ecosystem VendorProductAffected versions
npm sidorares mysql2 < 3.9.7
Fix: upgrade to 3.9.7
Root:npm rootio @rootio/mysql2 < 3.9.7-root.io.2
Fix: upgrade to 3.9.7-root.io.2
Root:npm GitHub Actions mysql2 < 3.9.7-aikido.2
Fix: upgrade to 3.9.7-aikido.2
Root:npm – mysql2 < 3.9.7-aikido.2
Fix: upgrade to 3.9.7-aikido.2
Original advisory text
CVE-2024-21511 in mysql2 - Patched by Root
Root has patched CVE-2024-21511 in the mysql2 package for Root:npm. Multiple fixed versions available.
Severity
9.8 Critical
CVSS 3.1: 9.8 (GHSA)
Exploitation
EPSS 1%
Type
CWE-94Code Injection
Timeline
Published11 Sep 2026
Updated22 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta