CVE-2015-9244: Mysqljs MySQL

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.

Affected products

  • Mysqljs MySQL: up to and including 0.9.6; version 2.0.0 only

Published 2018-05-29. Last modified 2026-06-17.