PT-2026-52608 · Unknown · Parse Server

CVE-2021-47987

·

Published

2021-09-07

·

Updated

2026-07-31

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 4.10.0
Description A supply chain incident occurred where incorrect version tags were pushed to the official repository. These tags pointed to an unreviewed personal fork of a contributor who had write access. Exposure occurred only if a project defined a git-based dependency referencing one of the affected tags. Although no malicious code was identified, the code was not reviewed or approved, meaning the introduction of security vulnerabilities cannot be ruled out.
Recommendations Update Parse Server to version 4.10.0 or later. Avoid using git-based dependencies that reference unverified version tags.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-PARSE-2021-47986
CVE-2021-47987
GHSA-593V-WCQX-HQ2W

Affected Products

Parse Server