CVE-2023-36475
CRITICALParse Server < 5.5.2 - Remote Code Execution via Prototype Pollution
Title source: llmDescription
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. A patch is available in versions 5.5.2 and 6.2.1.
References (7)
Core 7
Core References
Vendor Advisory x_refsource_confirm
https://github.com/parse-community/parse-server/security/advisories/GHSA-462x-c3jw-7vr6
Issue Tracking, Patch x_refsource_misc
https://github.com/parse-community/parse-server/issues/8674
Issue Tracking, Patch x_refsource_misc
https://github.com/parse-community/parse-server/issues/8675
Patch x_refsource_misc
https://github.com/parse-community/parse-server/commit/3dd99dd80e27e5e1d99b42844180546d90c7aa90
Patch x_refsource_misc
https://github.com/parse-community/parse-server/commit/5fad2928fb8ee17304abcdcf259932f827d8c81f
Release Notes x_refsource_misc
https://github.com/parse-community/parse-server/releases/tag/5.5.2
Release Notes x_refsource_misc
https://github.com/parse-community/parse-server/releases/tag/6.2.1
Scores
CVSS v3
9.8
EPSS
0.0268
EPSS Percentile
83.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-1321
Status
published
Products (2)
npm/parse-server
0 - 5.5.2npm
parseplatform/parse-server
< 5.5.2
Published
Jun 28, 2023
Tracked Since
Feb 18, 2026