Description
Calling an invalid Parse Server Cloud Function name or Cloud Job name crashes server and may allow for code injection.
Recommendation
Update the parse-server
package to the latest compatible version. Followings are version details:
Affected version(s): **>= 7.0.0-alpha.1, < 7.0.0-alpha.29 < 6.5.5** Patched version(s): **7.0.0-alpha.29 6.5.5**
References
Related Issues
- Vite's `server.fs` settings were not applied to HTML files - CVE-2025-58752
- OpenPGP.js's message signature verification can be spoofed - CVE-2025-47934
- Parse Server before v3.4.1 vulnerable to Denial of Service - CVE-2019-1020012
- Parse Server has an OAuth login vulnerability - CVE-2025-30168
- Tags:
- npm
- parse-server
Anything's wrong? Let us know Last updated on March 19, 2024