PT-2026-51112 · Unknown · Parse Server

Published

2026-06-19

·

Updated

2026-06-19

·

CVE-2026-55778

CVSS v4.0

2.1

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server (affected versions not specified)
Description The default fileUpload.fileExtensions blocklist can be bypassed by uploading files with non-standard or compound extensions combined with a dangerous content type. This allows the upload of files that browsers render as active content, such as HTML and SVG, leading to stored cross-site scripting (XSS), where an attacker injects malicious scripts into a web page viewed by other users. This issue is particularly impactful on storage adapters like S3 and GCS that persist and serve the attacker-supplied content type. While the GridFS/filesystem adapter uses the X-Content-Type-Options: nosniff header to mitigate browser rendering, the upload restriction is still bypassed.
Recommendations Configure fileUpload.fileExtensions as a strict allowlist containing only the necessary file extensions (e.g., ["^(png|jpe?g|gif|pdf)$"]) instead of using the default blocklist. Serve uploaded files from a separate domain than the application to isolate executed content from the application origin.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55778
GHSA-V8X7-R927-CC93

Affected Products

Parse Server