For regular (non-LiveQuery) queries, the session token is removed from the response, but for LiveQuery payloads it is currently not. If a user has a LiveQuery subscription on the Parse.User class, all session tokens created during user sign-ups will be broadcast as part of the LiveQuery payload.
Remove session token from LiveQuery payload.
Set user.acl(new Parse.ACL()) in a beforeSave trigger to make the user private already on sign-up.
{
"nvd_published_at": "2021-09-30T15:15:00Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-200"
],
"github_reviewed": true,
"github_reviewed_at": "2021-09-30T16:43:12Z"
}