PT-2026-24227 · Unknown · Parse Server
0Xkakash1
·
Published
2026-03-10
·
Updated
2026-03-18
·
CVE-2026-30941
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Parse Server versions prior to 8.6.14
Parse Server versions prior to 9.5.2-alpha.1
Description
Parse Server, an open-source backend deployable on Node.js infrastructures, contains a NoSQL injection issue. An unauthenticated attacker can inject MongoDB query operators through the
token field in the password reset and email verification resend endpoints. The token value is passed to database queries without type validation, potentially allowing extraction of password reset and email verification tokens. Deployments using MongoDB with email verification or password reset enabled are affected. When emailVerifyTokenReuseIfValid is configured, the email verification token can be fully extracted and used to verify a user's email address without inbox access. The affected API endpoints are the password reset and email verification resend endpoints.Recommendations
Versions prior to 8.6.14 should be updated to version 8.6.14 or later.
Versions prior to 9.5.2-alpha.1 should be updated to version 9.5.2-alpha.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Parse Server