Vulnerabilities/

Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint

Severity:
Medium

Description

The OAuth2 authentication adapter does not correctly validate app IDs when appidField and appIds are configured. During app ID validation, a malformed value is sent to the token introspection endpoint instead of the user’s actual access token.

Recommendation

Update the parse-server package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
parse-server
Anything's wrong? Let us know Last updated on March 13, 2026