CVE-2026-30848
Parse Server <8.6.8/9.5.0-alpha.8 - Path Traversal
Title source: llmDescription
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.8 and 9.5.0-alpha.8, the PagesRouter static file serving route is vulnerable to a path traversal attack that allows unauthenticated reading of files outside the configured pagesPath directory. The boundary check uses a string prefix comparison without enforcing a directory separator boundary. An attacker can use path traversal sequences to access files in sibling directories whose names share the same prefix as the pages directory (e.g. pages-secret starts with pages). This issue has been patched in versions 8.6.8 and 9.5.0-alpha.8.
Scores
EPSS
0.0008
EPSS Percentile
23.4%
Classification
CWE
CWE-22
Status
draft
Affected Products (1)
npm/parse-server
< 8.6.8npm
Timeline
Published
Mar 07, 2026
Tracked Since
Mar 08, 2026