Vulnerabilities/

Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`

Severity:
Medium

Description

The GET /sessions/me endpoint returns _Session fields that the server operator explicitly configured as protected via the protectedFields server option. Any authenticated user can retrieve their own session’s protected fields with a single request.

Recommendation

Update the parse-server package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
parse-server
Anything's wrong? Let us know Last updated on April 15, 2026