Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.
https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6591085
https://github.com/sidorares/node-mysql2/releases/tag/v3.9.4
https://github.com/sidorares/node-mysql2/pull/2572
https://github.com/sidorares/node-mysql2/commit/74abf9ef94d76114d9a09415e28b496522a94805
https://blog.slonser.info/posts/mysql2-attacker-configuration/