CVE-2026-55778
published 2026-07-08CVE-2026-55778: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.11 and 8.6.81, the default…
PriorityP416low2.1CVSS 4.0
AVNACLATPPRLUIPVCNVILVANSCLSILSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.41%
33.8th percentile
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.11 and 8.6.81, the default fileUpload.fileExtensions blocklist could be bypassed by uploading a file with a non-standard or compound extension and dangerous content type, allowing storage adapters such as S3 and GCS to serve attacker-supplied active content and enable stored cross-site scripting. This issue is fixed in versions 9.9.1-alpha.11 and 8.6.81.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| parse-community | parse-server | < 8.6.81 | 8.6.81 |
| parse-community | parse-server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
parse-community Parse Server up to 8.6.80/9.9.1-alpha.10 FileUpload cross site scripting
vuldb·2026-07-09·CVSS 2.1
CVE-2026-55778 [LOW] parse-community Parse Server up to 8.6.80/9.9.1-alpha.10 FileUpload cross site scripting
A vulnerability was found in parse-community Parse Server up to 8.6.80/9.9.1-alpha.10 and classified as problematic. This vulnerability affects unknown code of the component FileUpload. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-55778. The attack may be launched remotely. There is no exploit available.
GHSA
parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
ghsa·2026-06-19
CVE-2026-55778 [LOW] CWE-434 parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
### Impact
Parse Server's default `fileUpload.fileExtensions` blocklist is intended to prevent uploading files that browsers render as active content (such as HTML and SVG), which can be used to perform stored cross-site scripting (XSS) attacks against other users. The blocklist could be bypassed by uploading a file whose extension is not an exact match of a blocked extension (for example a non-standard or compound extension) together with a dangerous content type. On storage adapters that persist and serve the uploaded content type (such as S3 and GCS), the file is then served with the attacker-supplied content type, enabling stored XSS against users who open the file URL.
This affects th
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/parse-community/parse-server/commit/97c6a78d19f976ec756c1295f08a8fccab90799ahttps://github.com/parse-community/parse-server/commit/be12a60d65b6e140481882037fb896b1f951df50https://github.com/parse-community/parse-server/pull/10505https://github.com/parse-community/parse-server/pull/10506https://github.com/parse-community/parse-server/releases/tag/8.6.81https://github.com/parse-community/parse-server/releases/tag/9.9.1-alpha.11https://github.com/parse-community/parse-server/security/advisories/GHSA-v8x7-r927-cc93
2026-07-08
Published