PT-2026-52607 · Unknown · Parse Server

CVE-2021-47986

·

Published

2021-09-07

·

Updated

2026-07-31

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 4.10.0
Description A supply chain issue exists where incorrect version tags were pushed to the repository, linking to unreviewed code from a personal fork. This allows attackers to execute unreviewed and potentially malicious code by specifying the affected version tags in dependency declarations.
Recommendations Update Parse Server to version 4.10.0 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-PARSE-2021-47986
CVE-2021-47986
GHSA-593V-WCQX-HQ2W

Affected Products

Parse Server