Executive brief
Parse Server is a backend framework for building scalable applications. A vulnerability allows authenticated users to upload SVG files containing malicious JavaScript that executes in the context of the application, enabling attackers to steal user session tokens and hijack accounts. This affects all Parse Server deployments with file upload enabled (the default configuration).
Technical details
The vulnerability is a stored cross-site scripting (CWE-79) flaw in Parse Server's file upload handler. The default fileExtensions configuration blocks HTML files but fails to block SVG files, which are served inline with Content-Type: image/svg+xml without protective headers (X-Content-Type-Options: nosniff). An authenticated attacker can upload a specially crafted SVG file containing embedded JavaScript; when other users view or access the file, the script executes in the Parse Server origin, allowing theft of localStorage-based session tokens and account takeover. The vulnerability requires authentication and user interaction (victim viewing the malicious SVG). Patches are available in Parse Server 8.6.17 and 9.5.2-alpha.4, which add SVG to the default extension denylist.
Affected products
- Parse Community Parse Server all versions before 8.6.17, and 9.0.0 before 9.5.2-alpha.4
Timeline
- 2026-03-10: disclosed: Published in GitHub Security Advisory GHSA-hcj7-6gxh-24ww
- 2026-03-10: patched: Parse Server 8.6.17 and 9.5.2-alpha.4 released with fix