Vulnerabilities/

Parse Dashboard has incomplete authentication on AI Agent endpoint

Severity:
High

Description

The AI Agent API endpoint (POST /apps/:appId/agent) lacks authentication. Unauthenticated remote attackers can send requests to the endpoint and perform arbitrary database operations against any connected Parse Server using the master key.

Recommendation

Update the parse-dashboard package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
parse-dashboard
Anything's wrong? Let us know Last updated on February 25, 2026