← Back to browse · API

CVE-2022-39396

Severity
CRITICAL
CVSS
9.8
EPSS
0.38717
Risk score
52.75
CISA KEV
No
PoC
No
Published
2022-11-10
Modified
2025-04-23
First seen
2026-08-07
Aliases
EUVD-2022-7404, GHSA-PRM5-8G2M-24GG
Products
parse-community:parse-server 5.0.0, < 5.3.1, parse-community:parse-server < 4.10.18
Sources
euvd EUVD-2022-7404

Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnerable to Remote Code Execution via prototype pollution. An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. This issue is patched in version 5.3.1 and in 4.10.18. There are no known workarounds.

References