CVE-2026-55778: Parse-Community Parse-Server
Low severity, CVSS 2.1. EPSS: 0.6% chance of exploitation in the next 30 days.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.11 and 8.6.81, the default fileUpload.fileExtensions blocklist could be bypassed by uploading a file with a non-standard or compound extension and dangerous content type, allowing storage adapters such as S3 and GCS to serve attacker-supplied active content and enable stored cross-site scripting. This issue is fixed in versions 9.9.1-alpha.11 and 8.6.81.
Affected products
- Parse-Community Parse-Server: from 9.0.0-alpha.1, before 9.9.1-alpha.11 (fixed in 9.9.1-alpha.11); before 8.6.81 (fixed in 8.6.81)
Published 2026-07-08. Last modified 2026-07-10.