Executive brief
Parse Server is a backend framework used to build scalable application servers and APIs. An attacker can exploit improper input validation in database query handling to inject arbitrary SQL commands into PostgreSQL databases, potentially allowing them to read, modify, or delete sensitive data without authorization. This vulnerability only affects deployments using PostgreSQL; organizations using other database backends are not at risk.
Technical details
The vulnerability is a SQL injection (CWE-89) in Parse Server's handling of dot-notation field names in PostgreSQL queries. The root cause is improper escaping of sub-field values in dot-notation queries when used with the sort, distinct, and where query parameters. An unauthenticated attacker on the network can craft a malicious query request to inject SQL code and execute arbitrary commands on the PostgreSQL database. The attack requires no special privileges or user interaction. Patches are available: Parse Server 8.6.28 and later, and Parse Server 9.6.0-alpha.2 and later, fix the vulnerability by properly escaping characters in dot-notation sub-field values.
Affected products
- Parse Community Parse Server All versions prior to 8.6.28 and versions 9.0.0 to 9.6.0-alpha.2
Timeline
- 2026-03-10: disclosed: Vulnerability published by Parse Community
- 2026-03-10: patched: Parse Server 8.6.28 and 9.6.0-alpha.2 released with fixes