Vulnerabilities/

Parse Server vulnerable to schema poisoning via prototype pollution in deep copy

Severity:
Medium

Description

An attacker can bypass the default request keyword denylist protection and the class-level permission for adding fields by sending a crafted request that exploits prototype pollution in the deep copy mechanism.

Recommendation

Update the parse-server package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
parse-server
Anything's wrong? Let us know Last updated on March 19, 2026