PT-2025-42196 · Parse · Parse Javascript Sdk

CVE-2025-62374

·

Published

2025-10-14

·

Updated

2025-10-16

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Parse Javascript SDK versions prior to 7.0.0
Description A flaw exists in Parse Javascript SDK that, before version 7.0.0, allows for remote code execution through the injection of malicious payloads. The following components are impacted: ParseObject.fromJSON, ParseObject.pin, ParseObject.registerSubclass, ObjectStateMutations (internal), and encode/decode (internal).
Recommendations Update to version 7.0.0 or later.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62374
GHSA-9F2H-7V79-MXW3

Affected Products

Parse Javascript Sdk