Vulnerabilities/

parse is vulnerable to prototype pollution

Severity:
Medium

Description

parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

Recommendation

Update the parse package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
parse
Anything's wrong? Let us know Last updated on November 27, 2025