GHSA-9f2h-7v79-mxw3
Parse Javascript SDK vulnerable to prototype pollution in `Parse.Object` and internal APIs
Quick fix
GHSA-9f2h-7v79-mxw3 — parse: upgrade to the fixed version with the command below.
npm install parse@7.0.0Details
### Summary
Prototype pollution capabilities on various APIs.
### Details
Injection of malicious payload allows attacker to remotely execute arbitrary code. `Parse.Object` and internal APIs are affected, specifically: - `ParseObject.fromJSON` - `ParseObject.pin` - `ParseObject.registerSubclass` - `ObjectStateMutations` (internal) - `encode`/`decode` (internal)
### PoC
Demonstrative tests added as part of the fix.
### References
- https://github.com/parse-community/Parse-SDK-JS/security/advisories/GHSA-9f2h-7v79-mxw3 - Patch https://github.com/parse-community/Parse-SDK-JS/releases/tag/7.0.0-alpha.1
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/parse-community/Parse-SDK-JS/security/advisories/GHSA-9f2h-7v79-mxw3[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-62374[ADVISORY]
- https://github.com/parse-community/Parse-SDK-JS/pull/2749[WEB]
- https://github.com/parse-community/Parse-SDK-JS/commit/00973987f361368659c0c4dbf669f3897520b132[WEB]
- https://github.com/parse-community/Parse-SDK-JS[PACKAGE]
- https://github.com/parse-community/Parse-SDK-JS/releases/tag/7.0.0-alpha.1[WEB]