CVE Explorer
CVE-2026-30941
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14 and 9.5.2-alpha.1, NoSQL injection vulnerability allows an unauthenticated attacker to inject MongoDB query operators via the token field in the password reset and email verification resend endpoints. The token value is passed to database queries without type validation and can be used to extract password reset and email verification tokens. Any Parse Server deployment using Mo
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"parse-server","vendor":"parse-community","versions":[{"status":"affected","version":">= 9.0.0 < 9.5.2-alpha.1"},{"status":"affected","version":"< 8.6.14"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9042bdf89d8284ef313d479d63f56cab512d133abbdf0c91ff9090586f4072e2 · sha256:2cf12a1ec4255932… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9042bdf89d8284ef313d479d63f56cab512d133abbdf0c91ff9090586f4072e2 · sha256:2cf12a1ec4255932… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-943","description":"CWE-943: Improper Neutralization of Special Elements in Data Query Logic","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9042bdf89d8284ef313d479d63f56cab512d133abbdf0c91ff9090586f4072e2 · sha256:2cf12a1ec4255932… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/parse-community/parse-server/releases/tag/8.6.14","tags":["x_refsource_MISC"],"url":"https://github.com/parse-community/parse-server/releases/tag/8.6.14"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9042bdf89d8284ef313d479d63f56cab512d133abbdf0c91ff9090586f4072e2 · sha256:2cf12a1ec4255932… · /containers/cna/references/1
{"name":"https://github.com/parse-community/parse-server/releases/tag/9.5.2-alpha.1","tags":["x_refsource_MISC"],"url":"https://github.com/parse-community/parse-server/releases/tag/9.5.2-alpha.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9042bdf89d8284ef313d479d63f56cab512d133abbdf0c91ff9090586f4072e2 · sha256:2cf12a1ec4255932… · /containers/cna/references/2
{"name":"https://github.com/parse-community/parse-server/security/advisories/GHSA-vgjh-hmwf-c588","tags":["x_refsource_CONFIRM"],"url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-vgjh-hmwf-c588"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9042bdf89d8284ef313d479d63f56cab512d133abbdf0c91ff9090586f4072e2 · sha256:2cf12a1ec4255932… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.