mysql2 is vulnerable to Remote Code Execution (RCE)
85
High Risk
Affected versions of this package are vulnerable to Remote Code Execution (RCE) via the readCodeFor function, due to improper validation of the supportBigNumbers and bigNumberStrings values. This vulnerability is exploitable when using user-defined database connections.
You are affected if you are using a version of this package = 3.9.3.
mysql2 is vulnerable to Remote Code Execution (RCE) in versions 0.0.1 - 3.9.3.
Upgrade the mysql2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant