
Research
Security News
The Landscape of Malicious Open Source Packages: 2025 Mid‑Year Threat Report
A look at the top trends in how threat actors are weaponizing open source packages to deliver malware and persist across the software supply chain.
mysql-connector-python
Advanced tools
A self-contained Python driver for communicating with MySQL servers, using an API that is compliant with the Python Database API Specification v2.0 (PEP 249).
Supply Chain Security
Vulnerability
Quality
Maintenance
License
Network access
Supply chain riskThis module accesses the network.
Found 1 instance in 1 package
Uses eval
Supply chain riskPackage uses dynamic code execution (e.g., eval()), which is a dangerous practice. This can prevent the code from running in certain environments and increases the risk that the code may contain exploits or malicious behavior.
Found 1 instance in 1 package
Shell access
Supply chain riskThis module accesses the system shell. Accessing the system shell increases the risk of executing arbitrary code.
Found 1 instance in 1 package
.. image:: https://img.shields.io/pypi/v/mysql-connector-python.svg :target: https://pypi.org/project/mysql-connector-python/ .. image:: https://img.shields.io/pypi/pyversions/mysql-connector-python.svg :target: https://pypi.org/project/mysql-connector-python/ .. image:: https://img.shields.io/pypi/l/mysql-connector-python.svg :target: https://pypi.org/project/mysql-connector-python/
MySQL Connector/Python enables Python programs to access MySQL databases, using
an API that is compliant with the Python Database API Specification v2.0 (PEP 249) <https://www.python.org/dev/peps/pep-0249/>
_ - We refer to it as the
Classic API <https://dev.mysql.com/doc/connector-python/en/connector-python-reference.html>
_.
Asynchronous Connectivity <https://dev.mysql.com/doc/connector-python/en/connector-python-asyncio.html>
_C-extension <https://dev.mysql.com/doc/connector-python/en/connector-python-cext.html>
_Telemetry <https://dev.mysql.com/doc/connector-python/en/connector-python-opentelemetry.html>
_Connector/Python contains the classic and XDevAPI connector APIs, which are installed separately. Any of these can be installed from a binary or source distribution.
Binaries are distributed in the following package formats:
RPM <https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/packaging_and_distributing_software/introduction-to-rpm_packaging-and-distributing-software>
_WHEEL <https://packaging.python.org/en/latest/discussions/package-formats/#what-is-a-wheel>
_On the other hand, the source code is distributed as a compressed file from which a wheel package can be built.
The recommended way to install Connector/Python is via pip <https://pip.pypa.io/>
_,
which relies on WHEEL packages. For such a reason, it is the installation procedure
that is going to be described moving forward.
Please, refer to the official MySQL documentation Connector/Python Installation <https://dev.mysql.com/doc/connector-python/en/connector-python-installation.html>
_ to
know more about installing from an RPM, or building and installing a WHEEL package from
a source distribution.
Before installing a package with pip <https://pip.pypa.io/>
, it is strongly suggested
to have the most recent pip
version installed on your system.
If your system already has pip
installed, you might need to update it. Or you can use
the standalone pip installer <https://pip.pypa.io/en/latest/installation/>
.
.. code-block:: bash
$ pip install mysql-connector-python
++++++++++++++++++++ Installation Options ++++++++++++++++++++
Connector packages included in MySQL Connector/Python allow you to install optional dependencies to unleash certain functionalities.
.. code-block:: bash
# 3rd party packages to unleash the telemetry functionality are installed
$ pip install mysql-connector-python[telemetry]
This installation option can be seen as a shortcut to install all the dependencies needed by a particular feature. Mind that this is optional and you are free to install the required dependencies by yourself.
Available options:
.. code:: python
import mysql.connector
# Connect to server
cnx = mysql.connector.connect(
host="127.0.0.1",
port=3306,
user="mike",
password="s3cre3t!")
# Get a cursor
cur = cnx.cursor()
# Execute a query
cur.execute("SELECT CURDATE()")
# Fetch one result
row = cur.fetchone()
print("Current date is: {0}".format(row[0]))
# Close connection
cnx.close()
MySQL Connector/Python Developer Guide <https://dev.mysql.com/doc/connector-python/en/>
_
MySQL Connector/Python Forum <http://forums.mysql.com/list.php?50>
_
MySQL Public Bug Tracker <https://bugs.mysql.com>
_
Slack <https://mysqlcommunity.slack.com>
_ (Sign-up <https://lefred.be/mysql-community-on-slack/>
_ required if you do not have an Oracle account)
Stack Overflow <https://stackoverflow.com/questions/tagged/mysql-connector-python>
_
Oracle Blogs <https://blogs.oracle.com/search.html?q=connector-python>
_
There are a few ways to contribute to the Connector/Python code. Please refer
to the contributing guidelines <https://github.com/mysql/mysql-connector-python/blob/trunk/CONTRIBUTING.md>
_ for additional information.
Please refer to the README.txt <https://github.com/mysql/mysql-connector-python/blob/trunk/README.txt>
_ and LICENSE.txt <https://github.com/mysql/mysql-connector-python/blob/trunk/LICENSE.txt>
_
files, available in this repository, for further details.
FAQs
A self-contained Python driver for communicating with MySQL servers, using an API that is compliant with the Python Database API Specification v2.0 (PEP 249).
We found that mysql-connector-python demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A look at the top trends in how threat actors are weaponizing open source packages to deliver malware and persist across the software supply chain.
Security News
ESLint now supports HTML linting with 48 new rules, expanding its language plugin system to cover more of the modern web development stack.
Security News
CISA is discontinuing official RSS support for KEV and cybersecurity alerts, shifting updates to email and social media, disrupting automation workflows.