CVE-2025-53364

MEDIUM EXPLOITED NUCLEI

Parse Server <7.5.3-8.2.2 - Info Disclosure

Title source: llm

Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.0 and before 7.5.3 and 8.2.2, the Parse Server GraphQL API previously allowed public access to the GraphQL schema without requiring a session token or the master key. While schema introspection reveals only metadata and not actual data, this metadata can still expand the potential attack surface. This vulnerability is fixed in 7.5.3 and 8.2.2.

Nuclei Templates (1)

Parse Server - GraphQL Schema Information Disclosure
MEDIUMVERIFIEDby securitytaters
Shodan: http.title:"parse server" || "parse-server" || http.title:"parse dashboard"
FOFA: title="parse dashboard"

Scores

CVSS v3 5.3
EPSS 0.0045
EPSS Percentile 63.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

VulnCheck KEV 2025-12-01
CWE
CWE-497
Status published
Products (3)
npm/parse-server 8.0.0 - 8.2.2npm
parse-community/parse-server >= 5.3.0, < 7.5.3
parse-community/parse-server >= 8.0.0, < 8.2.2
Published Jul 10, 2025
Tracked Since Feb 18, 2026