PT-2026-24426 · Unknown · Parse Server

Restriction

·

Published

2026-03-10

·

Updated

2026-03-12

·

CVE-2026-30948

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 9.5.2-alpha.4 Parse Server versions prior to 8.6.17
Description Parse Server, an open source backend deployable on Node.js infrastructures, contains a stored cross-site scripting (XSS) issue. Authenticated users can upload SVG files containing JavaScript. These files are served inline with a Content-Type of image/svg+xml and lack protective headers, leading to the execution of embedded scripts within the Parse Server origin. This can potentially allow attackers to steal session tokens from localStorage and take over accounts. The default fileExtensions option does not block SVG files, which are a known XSS vector. All Parse Server deployments with file upload enabled for authenticated users are affected.
Recommendations Update to Parse Server version 9.5.2-alpha.4 or later. Update to Parse Server version 8.6.17 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-PARSE-2026-30948
CVE-2026-30948
GHSA-HCJ7-6GXH-24WW

Affected Products

Parse Server