Executive brief
Parse Server is a backend-as-a-service platform that provides REST APIs for data storage and management. A SQL injection vulnerability in the PostgreSQL storage adapter allows attackers to inject arbitrary SQL commands via crafted field names in Increment operations, potentially exposing sensitive database content or modifying data while bypassing access controls. This vulnerability only affects Parse Server instances using PostgreSQL databases.
Technical details
The vulnerability is a SQL injection (CWE-89) in the PostgreSQL storage adapter's handling of Increment operations on nested object fields using dot notation (e.g., stats.counter). The sub-key name is interpolated directly into SQL string literals without proper escaping, allowing an attacker to break out of the string context using single quotes. An attacker with network access to the Parse Server REST API and the ability to send write requests can inject arbitrary SQL to read, modify, or delete database contents, bypassing Class-Level Permissions (CLPs) and Access Control Lists (ACLs). Only PostgreSQL deployments are affected. Patches are available in Parse Server 8.6.31 and 9.6.0-alpha.5, which escape single quotes before interpolation.
Affected products
- Parse Community Parse Server All versions up to 8.6.30; versions 9.0.0-alpha.1 up to 9.6.0-alpha.4
Timeline
- 2026-03-10: disclosed: GitHub security advisory published
- 2026-03-11: patched: Parse Server 8.6.31 and 9.6.0-alpha.5 released