CVE-2026-33163
March 18, 2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a "Parse.Cloud.afterLiveQueryEvent" trigger is registered for a class, the LiveQuery server leaks protected fields and "authData" to all subscribers of that class. Fields configured as protected via Class-Level Permissions ("protectedFields") are included in LiveQuery event payloads for all event types (create, update, delete, enter, leave). Any user with sufficient CLP permissions to subscribe to the affected class can receive protected field data of other users, including sensitive personal information and OAuth tokens from third-party authentication providers. The vulnerability was caused by a reference detachment bug. When an "afterEvent" trigger is registered, the LiveQuery server converts the event object to a "Parse.Object" for the trigger, then creates a new JSON copy via "toJSONwithObjects()". The sensitive data filter was applied to the "Parse.Object" reference, but the unfiltered JSON copy was sent to clients. The fix in versions 9.6.0-alpha.35 and 8.6.50 ensures that the JSON copy is assigned back to the response object before filtering, so the filter operates on the actual data sent to clients. As a workaround, remove all "Parse.Cloud.afterLiveQueryEvent" trigger registrations. Without an "afterEvent" trigger, the reference detachment does not occur and protected fields are correctly filtered.
Affected Packages
https://github.com/parse-community/parse-server.git (GITHUB):
Affected version(s) >=9.0.0 <9.6.0-alpha.35Fix Suggestion:
Update to version 9.6.0-alpha.35https://github.com/parse-community/parse-server.git (GITHUB):
Affected version(s) >=2.0.0 <8.6.50Fix Suggestion:
Update to version 8.6.50parse-server (NPM):
Affected version(s) >=9.0.0 <9.6.0-alpha.35Fix Suggestion:
Update to version 9.6.0-alpha.35parse-server (NPM):
Affected version(s) >=1.0.0 <8.6.50Fix Suggestion:
Update to version 8.6.50parse-server (NPM):
Affected version(s) >=1.0.0 <8.6.50Fix Suggestion:
Update to version 8.6.50Related Resources (5)
Do you need more information?
Contact UsCVSS v4
Base Score:
8.2
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
HIGH
Vulnerable System Integrity
NONE
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
7.5
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE
Weakness Type (CWE)
Exposure of Sensitive Information to an Unauthorized Actor
EPSS
Base Score:
0.02