Junglewise Threat Intelligence

CVE-2026-35200: Parse Server stored XSS via Content-Type mismatch in file uploads

CVE-2026-35200 · Severity: medium · CVSS 5.4 · Published 2026-04-06

Technologies: Parse Platform Parse-Server.

Executive brief

Parse Server, an open-source backend for Node.js applications, contains a vulnerability in how it handles file uploads. An attacker can upload a file that appears harmless (like a text file) but is actually treated as a malicious web page (HTML) by the storage system. This could allow an attacker to perform cross-site scripting (XSS) attacks, potentially leading to the theft of user session data or unauthorized actions on the platform.

Technical details

A vulnerability exists in Parse Server's FilesController where the 'Content-Type' header provided during a file upload is not validated against the file's extension. An attacker with upload privileges can bypass extension allowlists by providing a permitted extension (e.g., .txt) while specifying a different MIME type (e.g., text/html) in the header. When using storage adapters that rely on the stored metadata to serve files (such as Amazon S3 or Google Cloud Storage), the file is served with the attacker-controlled MIME type, enabling stored XSS. The default GridFS adapter is unaffected as it derives MIME types from filenames at request time. The fix ensures the Content-Type is derived from the file extension, overriding user-provided headers.

Affected products

  • Parse Platform Parse Server < 8.6.73, >= 9.0.0 < 9.7.1-alpha.4

Timeline

  • 2026-04-02: patched: Fixes merged in PR #10383 and #10384
  • 2026-04-06: disclosed: Initial advisory published
  • 2026-04-06: advisory: NVD published CVE-2026-35200

References