CVE-2023-36475

CRITICAL

Parse Server <5.5.2, 6.2.1 - RCE

Title source: llm
STIX 2.1

Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. A patch is available in versions 5.5.2 and 6.2.1.

Scores

CVSS v3 9.8
EPSS 0.0983
EPSS Percentile 93.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-1321
Status published
Products (2)
npm/parse-server 0 - 5.5.2npm
parseplatform/parse-server < 5.5.2
Published Jun 28, 2023
Tracked Since Feb 18, 2026