GHSA-7m6r-fhh7-r47c

Suggest an improvement
Source
https://github.com/advisories/GHSA-7m6r-fhh7-r47c
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-7m6r-fhh7-r47c/GHSA-7m6r-fhh7-r47c.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7m6r-fhh7-r47c
Aliases
Published
2026-03-11T00:23:21Z
Modified
2026-03-14T03:41:10Z
Severity
  • 6.0 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Parse Server vulnerable to LDAP injection via unsanitized user input in DN and group filter construction
Details

Impact

The LDAP authentication adapter is vulnerable to LDAP injection. User-supplied input (authData.id) is interpolated directly into LDAP Distinguished Names (DN) and group search filters without escaping special characters. This allows an attacker with valid LDAP credentials to manipulate the bind DN structure and to bypass group membership checks. This enables privilege escalation from any authenticated LDAP user to a member of any restricted group.

The vulnerability affects Parse Server deployments that use the LDAP authentication adapter with group-based access control.

Patches

The vulnerability is fixed by escaping user input before interpolation into DN strings (per RFC 4514) and LDAP filter strings (per RFC 4515).

Workarounds

There is no known workaround.

References

Database specific
{
    "cwe_ids":  [
        "CWE-90"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-11T00:23:21Z",
    "nvd_published_at":  "2026-03-10T22:16:20Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / parse-server

Package

Affected ranges

Type
SEMVER
Events
Introduced
9.0.0-alpha.1
Fixed
9.5.2-alpha.13

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-7m6r-fhh7-r47c/GHSA-7m6r-fhh7-r47c.json"

npm / parse-server

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.6.26

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-7m6r-fhh7-r47c/GHSA-7m6r-fhh7-r47c.json"