Vulnerabilities/

Parse Dashboard is Missing Authorization for its Agent Endpoint

Severity:
High

Description

The AI Agent API endpoint (POST /apps/:appId/agent) does not enforce authorization. Authenticated users scoped to specific apps can access any other app’s agent endpoint by changing the app ID in the URL.

Recommendation

Update the parse-dashboard package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
parse-dashboard
Anything's wrong? Let us know Last updated on February 25, 2026