Intel

AIKIDO-2025-10131

parse-server is vulnerable to Weak Password Recovery Mechanism

Weak Password Recovery Mechanism Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 4, 2025

48

Medium Risk

This Affects:

JSparse-server
1.0.0 - 7.4.0
Fixed in 8.0.0
Are you affected? Scan for Free

TL;DR

Versions of this package impacted by this issue have a weak password recovery mechanism due to the inclusion of the username in password reset and email verification links. This exposes personally identifiable information in logs and allows full account compromise if the link is shared. Since the link already contains a perishable token, the username is unnecessary and should be removed to prevent attackers from identifying the affected account.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges.

Background info

parse-server is vulnerable to Weak Password Recovery Mechanism in versions 1.0.0 - 7.4.0.

How to fix this

Upgrade the parse-server library to the patch version.