CVE-2026-55778
Published:July 08, 2026
Updated:July 21, 2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.11 and 8.6.81, the default fileUpload.fileExtensions blocklist could be bypassed by uploading a file with a non-standard or compound extension and dangerous content type, allowing storage adapters such as S3 and GCS to serve attacker-supplied active content and enable stored cross-site scripting. This issue is fixed in versions 9.9.1-alpha.11 and 8.6.81.
Affected Packages
https://github.com/parse-community/parse-server.git (GITHUB):
Affected version(s) >=2.0.0 <8.6.81Fix Suggestion:
Update to version 8.6.81https://github.com/parse-community/parse-server.git (GITHUB):
Affected version(s) >=9.0.0 <9.9.1-alpha.11Fix Suggestion:
Update to version 9.9.1-alpha.11parse-server (NPM):
Affected version(s) >=9.0.0 <9.9.1-alpha.11Fix Suggestion:
Update to version 9.9.1-alpha.11parse-server (NPM):
Affected version(s) >=1.0.0 <8.6.81Fix Suggestion:
Update to version 8.6.81Related Resources (8)
Do you need more information?
Contact UsCVSS v4
Base Score:
2.1
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
PASSIVE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
LOW
Vulnerable System Availability
NONE
Subsequent System Confidentiality
LOW
Subsequent System Integrity
LOW
Subsequent System Availability
NONE
CVSS v3
Base Score:
4.1
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE
Weakness Type (CWE)
Unrestricted Upload of File with Dangerous Type
EPSS
Base Score:
0.41