PT-2026-64286 · Unknown · Parse Server
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Parse Server versions 9.0.0 through 9.10.0-alpha.4
Parse Server versions 8.2.2 through 8.6.85
Description
GraphQL validation error messages reveal the names of required custom input fields even when public introspection is disabled via the
graphQLPublicIntrospection variable. An attacker possessing only the public application id can trigger these errors to discover required non-null custom fields on classes they already reference by name. This behavior partially undermines the intent of hiding the schema. No stored data, credentials, optional field names, unreferenced class names, or Cloud Code function names are exposed.Recommendations
Update Parse Server to version 9.10.0-alpha.5 or later.
Update Parse Server to version 8.6.86 or later.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Parse Server