Vulnerabilities/

parse is vulnerable to prototype pollution

Severity:
Medium

Description

parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse version 5.3.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
parse
Anything's wrong? Let us know Last updated on September 26, 2025

This issue is available in SmartScanner Professional

See Pricing