Vulnerabilities/

Parse Dashboard is Missing CSRF Protection for its Agent Endpoint

Severity:
High

Description

The AI Agent API endpoint (POST /apps/:appId/agent) lacks CSRF protection. An attacker can craft a malicious page that, when visited by an authenticated dashboard user, submits requests to the agent endpoint using the victim’s session.

Recommendation

Update the parse-dashboard package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
parse-dashboard
Anything's wrong? Let us know Last updated on February 25, 2026