PT-2025-42196 · Parse · Parse Javascript Sdk

Published

2025-10-14

·

Updated

2025-10-16

·

CVE-2025-62374

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Parse Javascript SDK versions prior to 7.0.0
Description A flaw exists in Parse Javascript SDK that, before version 7.0.0, allows for remote code execution through the injection of malicious payloads. The following components are impacted: ParseObject.fromJSON, ParseObject.pin, ParseObject.registerSubclass, ObjectStateMutations (internal), and encode/decode (internal).
Recommendations Update to version 7.0.0 or later.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2025-62374
GHSA-9F2H-7V79-MXW3

Affected Products

Parse Javascript Sdk