Description
Calling an invalid Parse Server Cloud Function name or Cloud Job name crashes server and may allow for code injection.
Recommendation
Update the parse-server package to the latest compatible version. Followings are version details:
Affected version(s): **>= 7.0.0-alpha.1, < 7.0.0-alpha.29 < 6.5.5** Patched version(s): **7.0.0-alpha.29 6.5.5**
References
Related Issues
- Parse Server allows public `explain` queries which may expose sensitive database performance information and schema deta - CVE-2025-64502
- vite allows server.fs.deny bypass via backslash on Windows - CVE-2025-62522
- Parse Server before v3.4.1 vulnerable to Denial of Service - CVE-2019-1020012
- Astro's `X-Forwarded-Host` is reflected without validation - CVE-2025-61925
- Tags:
- npm
- parse-server
Anything's wrong? Let us know Last updated on March 19, 2024