Junglewise Threat Intelligence

CVE-2026-55778: Parse Server stored XSS via file upload extension bypass

CVE-2026-55778 · Severity: medium · CVSS 4 · Published 2026-07-08

Technologies: Parse Community Parse-Server. Vendors: Parse Community.

Executive brief

Parse Server, a popular open-source backend for Node.js applications, contains a security flaw in how it handles file uploads. An attacker can bypass security filters by using unusual file extensions to upload malicious files, such as scripts disguised as images. If these files are then accessed by other users, it could lead to unauthorized actions or data theft within the context of the application.

Technical details

A vulnerability in Parse Server's 'fileUpload.fileExtensions' blocklist allows attackers to bypass extension restrictions. By uploading files with non-standard or compound extensions (e.g., double extensions) and a dangerous MIME type, attackers can trick storage adapters like Amazon S3 or Google Cloud Storage into serving active content. This results in stored cross-site scripting (XSS) when the file is rendered in a victim's browser. The issue is rooted in insufficient validation of file extensions against the default blocklist. Patches are available in versions 9.9.1-alpha.11 and 8.6.81.

Affected products

  • parse-community parse-server >= 9.0.0-alpha.1, < 9.9.1-alpha.11; < 8.6.81

Timeline

  • 2026-06-16: patched: Fixes committed to repository
  • 2026-07-08: disclosed: CVE published

References