sidorares/node-mysql2 · error · Error

The field name ( ) can't be the same as an object's private…

Error message

The field name (${field}) can't be the same as an object's private property.

What it means

fieldEscape (lib/helpers.js:74-82) guards a blocklist of private object property names (__defineGetter__, __defineSetter__, __lookupGetter__, __lookupSetter__, __proto__). If a field name being escaped matches one of these, the driver throws, because emitting such a field name into SQL would collide with object internals and risk prototype-pollution-shaped behavior in downstream row-as-object mapping.

Solutions

  1. Rename the column in SQL via AS with a safe alias: SELECT __proto__ AS proto_val FROM t.
  2. Reject/sanitize user-supplied identifiers against the privateObjectProps blocklist before building queries.
  3. Use rowsAsArray to receive rows as arrays and avoid object-property mapping entirely.

Example fix

// before
const rows = conn.query('SELECT __proto__ FROM t');

// after
const rows = conn.query('SELECT `__proto__` AS proto_val FROM t');
Defensive patterns

Strategy: validation

Validate before calling

const privateObjectProps = new Set(['__defineGetter__','__defineSetter__','__lookupGetter__','__lookupSetter__','__proto__']);
function assertSafeField(name) {
  if (privateObjectProps.has(name)) throw new Error(`Refusing to use private-shaped field name: ${name}`);
}

Type guard

const isSafeFieldName = (name) => !privateObjectProps.has(name);

Prevention

When it happens

Trigger: A query that nests tables (nestTables) or aliases a column whose name is __proto__ or one of the legacy accessors; user-controlled input used as a column/field identifier without sanitization; a schema that legitimately has a column named __proto__.

Common situations: Accepting untrusted column names from a query string or request body; legacy schemas with reserved-shaped column names; ORM-generated aliases that collide.

Related errors


AI-assisted analysis of sidorares/node-mysql2@8b1f829d37 (2026-08-11). Data as JSON: /api/errors/d429942e5365e626. Report an issue: GitHub.

Appendix: source

Thrown at lib/helpers.js:76

  return !!list;
}

exports.typeMatch = typeMatch;

const privateObjectProps = new Set([
  '__defineGetter__',
  '__defineSetter__',
  '__lookupGetter__',
  '__lookupSetter__',
  '__proto__',
]);

exports.privateObjectProps = privateObjectProps;

const fieldEscape = (field, isEval = true) => {
  if (privateObjectProps.has(field)) {
    throw new Error(
      `The field name (${field}) can't be the same as an object's private property.`
    );
  }

  return isEval ? srcEscape(field) : field;
};
exports.fieldEscape = fieldEscape;

View on GitHub (pinned to 8b1f829d37)