Intel

AIKIDO-2026-10607

parse-server is vulnerable to Authentication Bypass

Authentication BypassGHSA-jpq4-7fmq-q5fj Published Apr 28, 2026

21

Low Risk

This Affects:

JSparse-server
6.0.0 - 8.6.75
Fixed in 8.6.76
Are you affected? Scan for Free

TL;DR

The package had a race condition in the MFA SMS OTP consumption flow where a single-use OTP could be accepted twice when two login requests were processed concurrently.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

parse-server is vulnerable to Authentication Bypass in versions 6.0.0 - 8.6.75.

How to fix this

Upgrade the parse-server library to the patch version.