Security: parse-community/parse-server
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
File creation and deletion bypasses `readOnlyMasterKey` write restrictionGHSA-xfh7-phr7-gr2x published
Mar 5, 2026 by mtrezzaModerate -
Endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any userGHSA-79wj-8rqv-jvp5 published
Mar 5, 2026 by mtrezzaHigh -
Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restrictionGHSA-vc89-5g3r-cmhh published
Mar 4, 2026 by mtrezzaHigh -
Account takeover via JWT algorithm confusion in Google auth adapterGHSA-4q3h-vp4r-prv2 published
Feb 25, 2026 by mtrezzaCritical -
Server-Side Request Forgery (SSRF) in Instagram OAuth AdapterGHSA-3f5f-xgrj-97pf published
Dec 16, 2025 by mtrezzaHigh -
Cross-Site Scripting (XSS) via password reset and email verification HTML pagesGHSA-jhgf-2h8h-ggxv published
Dec 16, 2025 by mtrezzaModerate -
GitHub repository RCEGHSA-6w8g-mgvv-3fcj published
Dec 11, 2025 by mtrezzaModerate -
Parse Server allows public `explain` query which may expose sensitive database performance information and schema detailsGHSA-7cx5-254x-cgrq published
Nov 8, 2025 by mtrezzaModerate -
Server-Side Request Forgery (SSRF) in File Upload via URI FormatGHSA-x4qj-2f4q-r4rx published
Nov 5, 2025 by mtrezzaHigh -
Denial-of-service via unbounded query complexity in REST and GraphQL APIGHSA-cmj3-wx7h-ffvg published
Mar 10, 2026 by mtrezzaHigh