> For the complete documentation index, see [llms.txt](https://mariadb.com/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mariadb.com/docs/release-notes/connectors/node.js/changelogs/3.x/3.4.7.md).

# Connector/Node.js 3.4.7 Changelog

<a href="https://mariadb.com/downloads/connectors/connectors-data-access/nodejs-connector" class="button primary">Download</a> <a href="/pages/C9Mw9HR2imyJUdcxAfsm" class="button secondary">Release Notes</a> <a href="/pages/N80XQAdYKpTbcKIRkp5t" class="button secondary">Changelog</a> <a href="/spaces/CjGYMsT2MVP4nd3IyW2L/pages/x5uWNz6Wb26ooKT9S74U" class="button secondary">Connector/Node.js Overview</a>

**Release date:** 7 Aug 2026

For the highlights of this release, see the [release notes](/docs/release-notes/connectors/node.js/3.x/3.4.7.md).

The revision number links will take you to the revision's page on GitHub. On [GitHub](https://github.com/MariaDB/mariadb-connector-nodejs) you can view more details of the revision and view diffs of the code modified in that revision.

* [Revision #67c931b](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/67c931b) - bump 3.4.7 version
* [Revision #144b8f4](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/144b8f4) - \[[CONJS-369](https://jira.mariadb.org/browse/CONJS-369)] Object keys interpolated as identifiers without escapeId in SET expansion
* [Revision #7670d90](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/7670d90) - \[[CONJS-368](https://jira.mariadb.org/browse/CONJS-368)] SQL injection in text protocol when session uses NO\_BACKSLASH\_ESCAPES
* [Revision #2314c03](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/2314c03) - \[[CONJS-367](https://jira.mariadb.org/browse/CONJS-367)] Uninitialized process memory leaked to server via malformed GeoJSON Polygon parameter
* [Revision #253b6f2](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/253b6f2) - \[[CONJS-363](https://jira.mariadb.org/browse/CONJS-363)] typeCast accessors return corrupted values with prepared statements
* [Revision #8e8be66](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/8e8be66) - \[[CONJS-358](https://jira.mariadb.org/browse/CONJS-358)] Refuse multi-part packet reassembly before authentication
* [Revision #58f7589](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/58f7589) - \[misc] test correction
* [Revision #081c0ad](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/081c0ad) - \[misc] correct CodeQL false positive
* [Revision #c1b0e76](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/c1b0e76) - \[[CONJS-357](https://jira.mariadb.org/browse/CONJS-357)] use codeql v4
* [Revision #e9734d7](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/e9734d7) - \[misc] test correction for restrictedAuth
* [Revision #74e3f7e](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/74e3f7e) - \[[CONJS-357](https://jira.mariadb.org/browse/CONJS-357)] Harden connection-string parsing on maintenance
* [Revision #6e57b95](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/6e57b95) - \[[CONJS-357](https://jira.mariadb.org/browse/CONJS-357)] Add JavaScript SAST: CodeQL workflow + eslint-plugin-security with CI lint gate
* [Revision #91c821b](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/91c821b) - \[misc] Escape server-supplied filename before building LOCAL INFILE validation regex

<sub>*This page is: Copyright © 2026 MariaDB. All rights reserved.*</sub>

{% @marketo/form formid="4316" formId="4316" %}
