sidorares/node-mysql2 · error · Error
The field name ( ) can't be the same as an object's private…
Error message
The field name (${field}) can't be the same as an object's private property. What it means
fieldEscape (lib/helpers.js:74-82) guards a blocklist of private object property names (__defineGetter__, __defineSetter__, __lookupGetter__, __lookupSetter__, __proto__). If a field name being escaped matches one of these, the driver throws, because emitting such a field name into SQL would collide with object internals and risk prototype-pollution-shaped behavior in downstream row-as-object mapping.
Solutions
- Rename the column in SQL via AS with a safe alias: SELECT __proto__ AS proto_val FROM t.
- Reject/sanitize user-supplied identifiers against the privateObjectProps blocklist before building queries.
- Use rowsAsArray to receive rows as arrays and avoid object-property mapping entirely.
Example fix
// before
const rows = conn.query('SELECT __proto__ FROM t');
// after
const rows = conn.query('SELECT `__proto__` AS proto_val FROM t'); Defensive patterns
Strategy: validation
Validate before calling
const privateObjectProps = new Set(['__defineGetter__','__defineSetter__','__lookupGetter__','__lookupSetter__','__proto__']);
function assertSafeField(name) {
if (privateObjectProps.has(name)) throw new Error(`Refusing to use private-shaped field name: ${name}`);
} Type guard
const isSafeFieldName = (name) => !privateObjectProps.has(name);
Prevention
- Never use untrusted input as a field/column identifier without an allowlist.
- Alias reserved-shaped columns with AS in the SELECT.
- Use rowsAsArray when the schema may contain odd column names.
When it happens
Trigger: A query that nests tables (nestTables) or aliases a column whose name is __proto__ or one of the legacy accessors; user-controlled input used as a column/field identifier without sanitization; a schema that legitimately has a column named __proto__.
Common situations: Accepting untrusted column names from a query string or request body; legacy schemas with reserved-shaped column names; ORM-generated aliases that collide.
Related errors
- Bind parameters must be array if namedPlaceholders…
- Bind parameters must not contain function(s). To pass the…
- Bind parameters must not contain undefined
- Bind parameters must not contain undefined. To pass SQL…
- "database" connection config property must be a string
AI-assisted analysis of sidorares/node-mysql2@8b1f829d37 (2026-08-11).
Data as JSON: /api/errors/d429942e5365e626.
Report an issue: GitHub.
Appendix: source
Thrown at lib/helpers.js:76
return !!list;
}
exports.typeMatch = typeMatch;
const privateObjectProps = new Set([
'__defineGetter__',
'__defineSetter__',
'__lookupGetter__',
'__lookupSetter__',
'__proto__',
]);
exports.privateObjectProps = privateObjectProps;
const fieldEscape = (field, isEval = true) => {
if (privateObjectProps.has(field)) {
throw new Error(
`The field name (${field}) can't be the same as an object's private property.`
);
}
return isEval ? srcEscape(field) : field;
};
exports.fieldEscape = fieldEscape;
View on GitHub (pinned to 8b1f829d37)