Executive brief
Parse Server, an open-source backend framework, contains a vulnerability in how it handles file uploads. An attacker can bypass security restrictions to upload malicious files (like SVG images containing scripts) by adding a dot to the end of a filename. If a user opens one of these files, the attacker could execute malicious code in the user's browser, potentially leading to unauthorized actions or data theft.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Parse Server's file upload handler. The default extension blocklist can be bypassed by appending a trailing dot to a filename (e.g., 'malicious.svg.'). This causes the extension parser to return an empty string, bypassing blocklist checks while preserving the attacker-supplied Content-Type. When stored in adapters like S3 or GCS that serve the original Content-Type, the file is delivered as an active type (e.g., image/svg+xml), executing scripts in the victim's browser. The vulnerability is patched in versions 9.9.1-alpha.4 and 8.6.79.
Affected products
- Parse Community parse-server >= 9.0.0, < 9.9.1-alpha.4; <= 8.6.78
Timeline
- 2026-06-12: advisory: NVD publication date
- 2026-06-19: disclosed: GitHub Advisory published