MEDIUM6.5
GHSA-9g8m-v378-pcg3
parse is vulnerable to prototype pollution
Quick fix
GHSA-9g8m-v378-pcg3 — parse: upgrade to the fixed version with the command below.
npm install parse@7.0.0-alpha.1Details
parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-57324[ADVISORY]
- https://github.com/parse-community/Parse-SDK-JS/commit/9e7c1bad472b1ed2463cbac567b8ec752ae5b4c9[WEB]
- https://github.com/VulnSageAgent/PoCs/blob/main/JavaScript/prototype-pollution/parse%405.3.0/index.js[WEB]
- https://github.com/VulnSageAgent/PoCs/tree/main/JavaScript/prototype-pollution/CVE-2025-57324[WEB]
- https://github.com/parse-community/Parse-SDK-JS[PACKAGE]