Vulnerabilities/

Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement

Severity:
Medium

Description

The requestKeywordDenylist security control can be bypassed by placing any nested object or array before a prohibited keyword in the request payload. This is caused by a logic bug that stops scanning sibling keys after encountering the first nested value.

Recommendation

Update the parse-server package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
parse-server
Anything's wrong? Let us know Last updated on March 10, 2026