parse
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting parsepage 1 of 1
- CVE-2025-57324MEDIUMCVSS 6.5EG 6.5✓ Fixed in 7.0.0-alpha.12025-09-24
parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse version 5.3.0 and before allows attackers to inject properties on Object.protot…
- CVE-2025-62374MEDIUMCVSS 6.4EG 6.4✓ Fixed in 7.0.02025-10-14
Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, injection of malicious payload allows attacker to remotely execute arbitrary code. ParseObject.fromJSON, ParseObject.pin, …
Check whether parse is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for parse CVEs against the assets you own.
Start Free Scan →