GHSA-cvwj-6c9h-jg6v
Parse Dashboard is Missing Authorization for its Agent Endpoint
Quick fix
GHSA-cvwj-6c9h-jg6v — parse-dashboard: upgrade to the fixed version with the command below.
npm install parse-dashboard@9.0.0-alpha.8Details
### Impact
The AI Agent API endpoint (`POST /apps/:appId/agent`) does not enforce authorization. Authenticated users scoped to specific apps can access any other app's agent endpoint by changing the app ID in the URL. Read-only users are given the full master key instead of the read-only master key and can supply write permissions in the request body to perform write and delete operations.
Affected are only dashboards with `agent` configuration enabled.
### Patches
The fix adds per-app authorization checks and restricts read-only users to the `readOnlyMasterKey` with write permissions stripped server-side.
### Workarounds
Remove the `agent` configuration block from your dashboard configuration. Dashboards without an `agent` config are not affected.
### Resources
- GitHub advisory: https://github.com/parse-community/parse-dashboard/security/advisories/GHSA-cvwj-6c9h-jg6v - Fixed in: https://github.com/parse-community/parse-dashboard/releases/tag/9.0.0-alpha.8
Are you affected?
Enter the version of the package you're using.
Affected packages
7.3.0-alpha.42Fixed in: 9.0.0-alpha.8npm install parse-dashboard@9.0.0-alpha.8