PT-2026-24758 · Bitnami+4 · Parse+1

Restriction

·

Published

2026-03-11

·

Updated

2026-03-13

·

CVE-2026-31868

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 9.6.0-alpha.4 Parse Server versions prior to 8.6.30
Description Parse Server allows an attacker to upload files with extensions or content types not blocked by the default configuration of the fileUpload.fileExtensions option. These files, potentially containing malicious code like JavaScript within SVG or XHTML files, can be executed when accessed through a URL, leading to a stored Cross-Site Scripting (XSS) issue. This can enable an attacker to steal session tokens, redirect users, or perform actions on behalf of other users. Affected file extensions and content types include .svgz, .xht, .xml, .xsl, .xslt, and content types application/xhtml+xml and application/xslt+xml for extensionless uploads. The vulnerability involves the fileUpload.fileExtensions option.
Recommendations For versions prior to 9.6.0-alpha.4, update to version 9.6.0-alpha.4 or later. For versions prior to 8.6.30, update to version 8.6.30 or later. Configure the fileUpload.fileExtensions server option to block the affected file extensions and content types.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-PARSE-2026-31868
CVE-2026-31868
GHSA-V5HF-F4C3-M5RV

Affected Products

Parse
Parse Server