3.7

CVE-2026-30848

Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.8 and 9.5.0-alpha.8, the PagesRouter static file serving route is vulnerable to a path traversal attack that allows unauthenticated reading of files outside the configured pagesPath directory. The boundary check uses a string prefix comparison without enforcing a directory separator boundary. An attacker can use path traversal sequences to access files in sibling directories whose names share the same prefix as the pages directory (e.g. pages-secret starts with pages). This issue has been patched in versions 8.6.8 and 9.5.0-alpha.8.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Parseplatform ≫ Parse-server SwPlatform node.js Version < 8.6.8
Parseplatform ≫ Parse-server SwPlatform node.js Version >= 9.0.0 < 9.5.0
Parseplatform ≫ Parse-server Version 9.5.0 Update alpha1 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.5.0 Update alpha2 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.5.0 Update alpha3 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.5.0 Update alpha4 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.5.0 Update alpha5 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.5.0 Update alpha6 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.5.0 Update alpha7 SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.227
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
security-advisories@github.com 6.3 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://github.com/parse-community/parse-server/security/advisories/GHSA-hm3f-q6rw-m6wh
Vendor Advisory