GHSA-qwc3-h9mg-4582
Parse Dashboard has incomplete authentication on AI Agent endpoint
Quick fix
GHSA-qwc3-h9mg-4582 — parse-dashboard: upgrade to the fixed version with the command below.
npm install parse-dashboard@9.0.0-alpha.8Details
### Impact
The AI Agent API endpoint (POST `/apps/:appId/agent`) lacks authentication. Unauthenticated remote attackers can send requests to the endpoint and perform arbitrary database operations against any connected Parse Server using the master key.
### Patches
The fix adds authentication middleware to the agent endpoint.
### Workarounds
Remove the `agent` configuration block from your dashboard configuration. Dashboards without an `agent` config are not affected.
### Resources
- GitHub advisory: https://github.com/parse-community/parse-dashboard/security/advisories/GHSA-qwc3-h9mg-4582 - Fixed in: https://github.com/parse-community/parse-dashboard/releases/tag/9.0.0-alpha.8
Are you affected?
Enter the version of the package you're using.
Affected packages
7.3.0-alpha.42Fixed in: 9.0.0-alpha.8npm install parse-dashboard@9.0.0-alpha.8References
- https://github.com/parse-community/parse-dashboard/security/advisories/GHSA-qwc3-h9mg-4582[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-27595[ADVISORY]
- https://github.com/parse-community/parse-dashboard/commit/f92a9ef5246d57e51696bd881a15f3b133b2bb50[WEB]
- https://github.com/parse-community/parse-dashboard[PACKAGE]
- https://github.com/parse-community/parse-dashboard/releases/tag/9.0.0-alpha.8[WEB]