From 16f2a87c8465ac9a2b28234fd15a3b21e9de6871 Mon Sep 17 00:00:00 2001 From: anupamme Date: Wed, 23 Sep 2026 20:19:52 +0000 Subject: [PATCH] fix: multi_agent.cwe-416 security vulnerability Automated security fix generated by OrbisAI Security --- src/odbc_cursor.cpp | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/src/odbc_cursor.cpp b/src/odbc_cursor.cpp index 4428640..c7a0cfd 100644 --- a/src/odbc_cursor.cpp +++ b/src/odbc_cursor.cpp @@ -84,9 +84,13 @@ class FetchAsyncWorker : public ODBCAsyncWorker { public: FetchAsyncWorker(ODBCCursor* cursor, Napi::Function& callback) - : ODBCAsyncWorker(callback), cursor(cursor), data(cursor->data) {} + : ODBCAsyncWorker(callback), cursor(cursor), data(cursor->data) { + // Keep the JS-side cursor object alive (preventing GC from running its + // destructor, which frees data->hstmt) while this worker is in flight. + this->cursor->Ref(); + } - ~FetchAsyncWorker() {} + ~FetchAsyncWorker() { this->cursor->Unref(); } void Execute() { SQLRETURN return_code; @@ -155,9 +159,13 @@ class CursorCloseAsyncWorker : public ODBCAsyncWorker { public: CursorCloseAsyncWorker(ODBCCursor* cursor, Napi::Function& callback) - : ODBCAsyncWorker(callback), odbcCursor(cursor), data(cursor->data) {} + : ODBCAsyncWorker(callback), odbcCursor(cursor), data(cursor->data) { + // Keep the JS-side cursor object alive (preventing GC from running its + // destructor, which frees data->hstmt) while this worker is in flight. + this->odbcCursor->Ref(); + } - ~CursorCloseAsyncWorker() {} + ~CursorCloseAsyncWorker() { this->odbcCursor->Unref(); } void Execute() {