highVulnerability

GHSA-3f6p-5ww8-9rcr

## Summary A rogue MySQL server (or MITM) can force mysql2 to send credentials in **plaintext** by requesting an auth switch to `mysql_clear_password`. The driver complies without verifying that TLS is active. ## Details `mysql_clear_password` is registered as a default standard plugin in `lib/commands/auth_switch.js` (line 21). When a server sends an AuthSwitchRequest (0xFE) requesting `mysql_clear_password`, the driver executes it without checking for TLS. The plugin (`lib/auth_plugins/mysql_clear_password.js`) returns `Buffer.from(password + '\0')`. Note: `caching_sha2_password` plugin DOES check for SSL before sending cleartext (line 77). But `mysql_clear_password` has no such guard. ## Attack Scenario 1. Attacker operates rogue MySQL server or performs MITM 2. Server advertises `caching_sha2_password` in handshake 3. Client sends hashed auth response 4. Server replies with AuthSwitchRequest to `mysql_clear_password` 5. Client sends password in plaintext 6. Attacker captures plaintext password ## PoC Rogue MySQL server (Node.js, ~80 lines) that captures plaintext passwords from mysql2 clients. Tested against mysql2 3.20.0. Full PoC available on request. ## Suggested Fix Remove `mysql_clear_password` from `standardAuthPlugins`, or add a guard requiring TLS/unix socket before allowing cleartext auth. ## Impact - mysql2: 9M weekly downloads - Any application connecting without TLS is vulnerable to credential theft - Cloud environments with untrusted network paths are especially at risk

Properties

ghsa_id
GHSA-3f6p-5ww8-9rcr
severity
high
summary
MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
cve_id
GHSA-3f6p-5ww8-9rcr
is_ghsa_only
true
ghsa_published
2026-09-01T16:40:34Z
source_url
https://github.com/advisories/GHSA-3f6p-5ww8-9rcr
ghsa_updated
2026-09-01T16:40:35Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/mysql2

AFFECTS (1)

[Software]npm/mysql2

HAS_WEAKNESS (1)

[Weakness]Insufficiently Protected Credentials

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-3f6p-5ww8-9rcr — Ninja Signal Threat Intelligence | Ninja Signal