Loading...
Skip to main content
npm (Node.js)

parse-server Security Analysis

parse-server has 17 known security vulnerabilities in npm (Node.js). Upgrade to version 9.7.0-alpha.11 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

17 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Recommended safe version: 9.7.0-alpha.11

Upgrading to 9.7.0-alpha.11 or later resolves all 17 known vulnerabilities in parse-server. Run: npm install parse-server@9.7.0-alpha.11

Is parse-server in your project?

Check if you're affected and upgrade to 9.7.0-alpha.11 to stay secure.

17
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

17 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2026-30966
Parse Server has role escalation and CLP bypass via direct `_Join` table write
CRITICAL
All versions9.5.2-alpha.7, 8.6.20
CVE-2026-30965
Parse Server vulnerable to session token exfiltration via `redirectClassNameForKey` query parameter
CRITICAL
All versions9.5.2-alpha.8, 8.6.21
CVE-2026-31871
Parse Server vulnerable to SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL
CRITICAL
All versions9.6.0-alpha.5, 8.6.31
CVE-2026-31840
Parse Server: SQL injection via dot-notation field name in PostgreSQL
CRITICAL
All versions9.6.0-alpha.2, 8.6.28
CVE-2024-27298
ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection
CRITICAL
All versions6.5.0, 7.0.0-alpha.20
CVE-2024-39309
ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
CRITICAL
All versions6.5.7, 7.1.0
CVE-2026-32248
Parse Server: Account takeover via operator injection in authentication data identifier
CRITICAL
All versions9.6.0-alpha.12, 8.6.38
CVE-2026-31856
Parse Server vulnerable to SQL injection via `Increment` operation on nested object field in PostgreSQL
CRITICAL
All versions9.6.0-alpha.3, 8.6.29
CVE-2026-30863
Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters
CRITICAL
All versions9.5.0-alpha.11, 8.6.10
CVE-2026-27804
Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter
CRITICAL
All versions9.3.1-alpha.4, 8.6.3
CVE-2023-36475
Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution
CRITICAL
All versions5.5.2, 6.2.1
CVE-2026-34532
parse-server has cloud function validator bypass via prototype chain traversal
CRITICAL
All versions9.7.0-alpha.11, 8.6.67
CVE-2022-39396
Remote code execution via MongoDB BSON parser through prototype pollution
CRITICAL
All versions4.10.18, 5.3.1
CVE-2026-33409
Parse Server has an auth provider validation bypass on login via partial authData
HIGH
All versions9.6.0-alpha.41, 8.6.52
CVE-2026-30948
Parse Server vulnerable to stored cross-site scripting (XSS) via SVG file upload
HIGH
All versions9.5.2-alpha.4, 8.6.17
CVE-2026-31800
Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes
HIGH
All versions9.5.2-alpha.12, 8.6.25
CVE-2026-31868
Parse Server vulnerable to stored XSS via file upload of HTML-renderable file types
MEDIUM
All versions9.6.0-alpha.4, 8.6.30

About This Data

Vulnerability data for parse-server is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related npm (Node.js) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of parse-server.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed