Junglewise Threat Intelligence

CVE-2026-53724: Parse Server stored XSS via trailing dot filename bypass

CVE-2026-53724 · Severity: medium · CVSS 4 · Published 2026-06-12

Technologies: Parse Community Parse-Server. Vendors: Parse Community.

Executive brief

Parse Server, an open-source backend framework, contains a vulnerability in how it handles file uploads. An attacker can bypass security restrictions to upload malicious files (like SVG images containing scripts) by adding a dot to the end of a filename. If a user opens one of these files, the attacker could execute malicious code in the user's browser, potentially leading to unauthorized actions or data theft.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Parse Server's file upload handler. The default extension blocklist can be bypassed by appending a trailing dot to a filename (e.g., 'malicious.svg.'). This causes the extension parser to return an empty string, bypassing blocklist checks while preserving the attacker-supplied Content-Type. When stored in adapters like S3 or GCS that serve the original Content-Type, the file is delivered as an active type (e.g., image/svg+xml), executing scripts in the victim's browser. The vulnerability is patched in versions 9.9.1-alpha.4 and 8.6.79.

Affected products

  • Parse Community parse-server >= 9.0.0, < 9.9.1-alpha.4; <= 8.6.78

Timeline

  • 2026-06-12: advisory: NVD publication date
  • 2026-06-19: disclosed: GitHub Advisory published

References