Security: parse-community/parse-server
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Schema poisoning via prototype pollution in deep copyGHSA-9ccr-fpp6-78qf published
Mar 16, 2026 by mtrezzaModerate -
Protected fields bypass via LiveQuery subscription WHERE clauseGHSA-j7mm-f4rv-6q6q published
Mar 10, 2026 by mtrezzaModerate -
SQL injection via query field name when using PostgreSQLGHSA-c442-97qw-j6c6 published
Mar 11, 2026 by mtrezzaModerate -
Stored XSS via file upload of HTML-renderable file typesGHSA-v5hf-f4c3-m5rv published
Mar 10, 2026 by mtrezzaModerate -
SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQLGHSA-gqpp-xgvh-9h7h published
Mar 10, 2026 by mtrezzaCritical -
SQL injection via `Increment` operation on nested object field in PostgreSQLGHSA-q3vj-96h2-gwvg published
Mar 10, 2026 by mtrezzaCritical -
Protected fields bypass via dot-notation in query and sortGHSA-r2m8-pxm9-9c4g published
Mar 10, 2026 by mtrezzaHigh -
SQL injection via dot-notation field name in PostgreSQLGHSA-qpr4-jrj4-6f27 published
Mar 10, 2026 by mtrezzaCritical -
Denial of service via unindexed database query for unconfigured auth providersGHSA-g4cf-xj29-wqqr published
Mar 21, 2026 by mtrezzaHigh -
MFA recovery codes not consumed after useGHSA-4hf6-3x24-c9m8 published
Mar 10, 2026 by mtrezzaHigh