An express module providing a Parse-compatible API server
71%
Total Score
100
29
100
40
0
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-898030 New parse-server is vulnerable to Information Disclosure in versions 8.2.2 - 8.6.86 and 9.0.0 - 9.9.0. | 8.2.2 - 8.6.869.0.0 - 9.9.0 | Medium |
CVE-2026-55778 parse-server is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 9.0.0 - 9.9.1-alpha.11 and 0.0.0 - 8.6.80. | 0.0.0 - 8.6.809.0.0 - 9.9.1-alpha.11 | Low |
CVE-2026-53726 parse-server is vulnerable to Authorization Bypass Through User-Controlled Key in versions 9.0.0 - 9.9.1-alpha.6 and 0.0.0 - 8.6.80. | 0.0.0 - 8.6.809.0.0 - 9.9.1-alpha.6 | Medium |
CVE-2026-53725 parse-server is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 9.8.0 - 9.9.1-alpha.5. | 9.8.0 - 9.9.1-alpha.5 | Medium |
CVE-2026-53724 parse-server is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 9.0.0 - 9.9.1-alpha.4 and 0.0.0 - 8.6.78. | 0.0.0 - 8.6.789.0.0 - 9.9.1-alpha.4 | Low |
| Dependency | Last Release | Score |
|---|---|---|
ws Version 8.20.0 | — | — |
tv4 Version 1.3.0 | — | — |
cors Version 2.8.6 | — | — |
mime Version 4.1.0 | — | — |
parse Version 8.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant