fast mysql driver. Implements core protocol, prepared statements, ssl and compression in native JS
97%
Total Score
100
81
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-765062 mysql2 is vulnerable to Insufficiently Protected Credentials in versions 3.0.0 - 3.21.1. | 3.0.0 - 3.21.1 | High |
AIKIDO-2026-448685 mysql2 is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 3.23.0. | 0.0.1 - 3.23.0 | Medium |
AIKIDO-2026-10225 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. mysql2 is vulnerable to SQL Injection in versions 0.0.1 - 3.16.3. | 0.0.1 - 3.16.3 | High |
CVE-2024-21512 mysql2 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 3.9.8. | 0.0.0 - 3.9.8 | High |
AIKIDO-2024-10037 mysql2 is vulnerable to Remote Code Execution (RCE) in versions 2.0.0 - 3.9.6. | 2.0.0 - 3.9.6 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
long Version ^5.3.2 | — | — |
lru.min Version ^1.1.4 | — | — |
iconv-lite Version ^0.7.3 | — | — |
sql-escaper Version ^1.5.1 | — | — |
aws-ssl-profiles Version ^1.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant