mysql2 is vulnerable to Prototype Poisoning
65
Medium Risk
Versions of the mysql2 package prior to 3.9.4 are vulnerable to prototype poisoning due to insecure creation of the results object and improper sanitization of user input passed through the parserFn in text_parser.js and binary_parser.js.
You are affected if you are using a version of this package = 3.9.3.
mysql2 is vulnerable to Prototype Poisoning in versions 0.0.1 - 3.9.3.
Upgrade the mysql2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant