Executive brief
Parse Server, an open-source backend for Node.js applications, contains a vulnerability in how it handles file uploads. An attacker can upload a file that appears harmless (like a text file) but is actually treated as a malicious web page (HTML) by the storage system. This could allow an attacker to perform cross-site scripting (XSS) attacks, potentially leading to the theft of user session data or unauthorized actions on the platform.
Technical details
A vulnerability exists in Parse Server's FilesController where the 'Content-Type' header provided during a file upload is not validated against the file's extension. An attacker with upload privileges can bypass extension allowlists by providing a permitted extension (e.g., .txt) while specifying a different MIME type (e.g., text/html) in the header. When using storage adapters that rely on the stored metadata to serve files (such as Amazon S3 or Google Cloud Storage), the file is served with the attacker-controlled MIME type, enabling stored XSS. The default GridFS adapter is unaffected as it derives MIME types from filenames at request time. The fix ensures the Content-Type is derived from the file extension, overriding user-provided headers.
Affected products
- Parse Platform Parse Server < 8.6.73, >= 9.0.0 < 9.7.1-alpha.4
Timeline
- 2026-04-02: patched: Fixes merged in PR #10383 and #10384
- 2026-04-06: disclosed: Initial advisory published
- 2026-04-06: advisory: NVD published CVE-2026-35200