9.1

CVE-2026-30965

Parse Server session token exfiltration via `redirectClassNameForKey` query parameter

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerability in Parse Server's query handling allows an authenticated or unauthenticated attacker to exfiltrate session tokens of other users by exploiting the redirectClassNameForKey query parameter. Exfiltrated session tokens can be used to take over user accounts. The vulnerability requires the attacker to be able to create or update an object with a new relation field, which depends on the Class-Level Permissions of at least one class. This vulnerability is fixed in 9.5.2-alpha.8 and 8.6.21.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Parseplatform ≫ Parse-server SwPlatform node.js Version < 8.6.21
Parseplatform ≫ Parse-server SwPlatform node.js Version >= 9.0.0 < 9.5.2
Parseplatform ≫ Parse-server Version 9.5.2 Update alpha1 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.5.2 Update alpha2 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.5.2 Update alpha3 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.5.2 Update alpha4 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.5.2 Update alpha5 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.5.2 Update alpha6 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.5.2 Update alpha7 SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.09% 0.624
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
security-advisories@github.com 9.9 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://github.com/parse-community/parse-server/security/advisories/GHSA-6r2j-cxgf-495f
Vendor Advisory
Mitigation
https://github.com/parse-community/parse-server/releases/tag/8.6.21
Product
Release Notes
https://github.com/parse-community/parse-server/releases/tag/9.5.2-alpha.8
Product
Release Notes