CVE-2023-36475

CRITICAL

Parse Server < 5.5.2 - Remote Code Execution via Prototype Pollution

Title source: llm
STIX 2.1

Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. A patch is available in versions 5.5.2 and 6.2.1.

Scores

CVSS v3 9.8
EPSS 0.0268
EPSS Percentile 83.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-1321
Status published
Products (2)
npm/parse-server 0 - 5.5.2npm
parseplatform/parse-server < 5.5.2
Published Jun 28, 2023
Tracked Since Feb 18, 2026