mysql2 is vulnerable to Remote Code Execution (RCE)
90
Critical Risk
Affected versions of this package are vulnerable to Remote Code Execution (RCE) via the readCodeFor function (lib/parsers/text_parser.js and lib/parsers/binary_parser.js) due to improper validation of the 'timezone' value.
You are affected if you are using a version that falls within the vulnerable range.
mysql2 is vulnerable to Remote Code Execution (RCE) in versions 2.0.0 - 3.9.6.
Upgrade the mysql2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant