PT-2026-58924 · Bitnami · Parse
Published
2026-07-14
·
Updated
2026-07-14
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1 and 8.6.81, the default fileUpload.fileExtensions blocklist could be bypassed by uploading a file with a non-standard or compound extension and dangerous content type, allowing storage adapters such as S3 and GCS to serve attacker-supplied active content and enable stored cross-site scripting. This issue is fixed in versions 9.9.1 and 8.6.81.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Parse