Vulnerabilities/

Parse Server has a LiveQuery protected-field guard bypass via array-like logical operator value

Severity:
Medium

Description

An authenticated user with find class-level permission can bypass the protectedFields class-level permission setting on LiveQuery subscriptions.

Recommendation

Update the parse-server package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
parse-server
Anything's wrong? Let us know Last updated on April 01, 2026