CVE-2023-36475: Parseplatform Parse-Server

Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. A patch is available in versions 5.5.2 and 6.2.1.

Affected products

  • Parseplatform Parse-Server: before 5.5.2 (fixed in 5.5.2); from 6.0.0, before 6.2.1 (fixed in 6.2.1)

Published 2023-06-28. Last modified 2026-06-17.