fast mysql driver. Implements core protocol, prepared statements, ssl and compression in native JS
92%
Total Score
60
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10225 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. mysql2 is vulnerable to SQL Injection in versions 0.0.1 - 3.16.3. | 0.0.1 - 3.16.3 | High |
CVE-2024-21512 mysql2 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 3.9.8. | 0.0.0 - 3.9.8 | High |
AIKIDO-2024-10037 mysql2 is vulnerable to Remote Code Execution (RCE) in versions 2.0.0 - 3.9.6. | 2.0.0 - 3.9.6 | Critical |
AIKIDO-2024-10019 mysql2 is vulnerable to Prototype Poisoning in versions 0.0.1 - 3.9.3. | 0.0.1 - 3.9.3 | Medium |
AIKIDO-2024-10020 mysql2 is vulnerable to Remote Code Execution (RCE) in versions 0.0.1 - 3.9.3. | 0.0.1 - 3.9.3 | High |
| Dependency | Last Release | Score |
|---|---|---|
long Version ^5.3.2 | — | — |
denque Version ^2.1.0 | — | — |
lru.min Version ^1.1.4 | — | — |
iconv-lite Version ^0.7.2 | — | — |
sql-escaper Version ^1.3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant