parse-server Security Analysis
parse-server has 17 known security vulnerabilities in npm (Node.js). Upgrade to version 9.7.0-alpha.11 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 9.7.0-alpha.11
Upgrading to 9.7.0-alpha.11 or later resolves all 17 known vulnerabilities in parse-server. Run: npm install parse-server@9.7.0-alpha.11
Is parse-server in your project?
Check if you're affected and upgrade to 9.7.0-alpha.11 to stay secure.
Vulnerabilities
17 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2026-30966 Parse Server has role escalation and CLP bypass via direct `_Join` table write | CRITICAL | All versions | 9.5.2-alpha.7, 8.6.20 |
| CVE-2026-30965 Parse Server vulnerable to session token exfiltration via `redirectClassNameForKey` query parameter | CRITICAL | All versions | 9.5.2-alpha.8, 8.6.21 |
| CVE-2026-31871 Parse Server vulnerable to SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL | CRITICAL | All versions | 9.6.0-alpha.5, 8.6.31 |
| CVE-2026-31840 Parse Server: SQL injection via dot-notation field name in PostgreSQL | CRITICAL | All versions | 9.6.0-alpha.2, 8.6.28 |
| CVE-2024-27298 ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection | CRITICAL | All versions | 6.5.0, 7.0.0-alpha.20 |
| CVE-2024-39309 ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability | CRITICAL | All versions | 6.5.7, 7.1.0 |
| CVE-2026-32248 Parse Server: Account takeover via operator injection in authentication data identifier | CRITICAL | All versions | 9.6.0-alpha.12, 8.6.38 |
| CVE-2026-31856 Parse Server vulnerable to SQL injection via `Increment` operation on nested object field in PostgreSQL | CRITICAL | All versions | 9.6.0-alpha.3, 8.6.29 |
| CVE-2026-30863 Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters | CRITICAL | All versions | 9.5.0-alpha.11, 8.6.10 |
| CVE-2026-27804 Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter | CRITICAL | All versions | 9.3.1-alpha.4, 8.6.3 |
| CVE-2023-36475 Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution | CRITICAL | All versions | 5.5.2, 6.2.1 |
| CVE-2026-34532 parse-server has cloud function validator bypass via prototype chain traversal | CRITICAL | All versions | 9.7.0-alpha.11, 8.6.67 |
| CVE-2022-39396 Remote code execution via MongoDB BSON parser through prototype pollution | CRITICAL | All versions | 4.10.18, 5.3.1 |
| CVE-2026-33409 Parse Server has an auth provider validation bypass on login via partial authData | HIGH | All versions | 9.6.0-alpha.41, 8.6.52 |
| CVE-2026-30948 Parse Server vulnerable to stored cross-site scripting (XSS) via SVG file upload | HIGH | All versions | 9.5.2-alpha.4, 8.6.17 |
| CVE-2026-31800 Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes | HIGH | All versions | 9.5.2-alpha.12, 8.6.25 |
| CVE-2026-31868 Parse Server vulnerable to stored XSS via file upload of HTML-renderable file types | MEDIUM | All versions | 9.6.0-alpha.4, 8.6.30 |
About This Data
Vulnerability data for parse-server is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related npm (Node.js) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of parse-server.