Executive brief
Parse Server is an open-source backend used to power mobile and web applications. A flaw in its real-time update feature (LiveQuery) could allow sensitive information, such as authentication data or protected database fields, to be accidentally shared with unauthorized users. This occurs when multiple users are watching the same data at the same time, potentially leading to data leaks or incomplete information being sent to legitimate users.
Technical details
A race condition exists in Parse Server's LiveQuery implementation due to the use of shared mutable objects across concurrent subscriber event handlers. The sensitive data filter modifies these objects in-place; if one subscriber's filter removes a protected field, subsequent subscribers in the same execution cycle may receive the already-filtered object, or conversely, bypass filters if the state is inconsistent. This also affects Cloud Code 'afterEvent' triggers, where modifications from one subscriber can leak to others. An attacker with a valid account could potentially receive sensitive fields or authentication data belonging to other subscribers of the same class. The issue is fixed in versions 8.6.65 and 9.7.0-alpha.9.
Affected products
- Parse Platform Parse Server < 8.6.65, >= 9.0.0 < 9.7.0-alpha.9
Timeline
- 2026-03-31: advisory: NVD publication date
- 2026-03-27: patched: Fixes committed to GitHub repository
References
- https://github.com/parse-community/parse-server/commit/5834e29234593addaa0251a85f572ad4f376320b
- https://github.com/parse-community/parse-server/commit/776c71c3078e77d38c94937f463741793609d055
- https://github.com/parse-community/parse-server/pull/10330
- https://github.com/parse-community/parse-server/pull/10331
- https://github.com/parse-community/parse-server/security/advisories/GHSA-m983-v2ff-wq65