GHSA-v8x7-r927-cc93

Suggest an improvement
Source
https://github.com/advisories/GHSA-v8x7-r927-cc93
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-v8x7-r927-cc93/GHSA-v8x7-r927-cc93.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v8x7-r927-cc93
Aliases
Published
2026-06-19T19:36:36Z
Modified
2026-07-14T16:40:35Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
Details

Impact

Parse Server's default fileUpload.fileExtensions blocklist is intended to prevent uploading files that browsers render as active content (such as HTML and SVG), which can be used to perform stored cross-site scripting (XSS) attacks against other users. The blocklist could be bypassed by uploading a file whose extension is not an exact match of a blocked extension (for example a non-standard or compound extension) together with a dangerous content type. On storage adapters that persist and serve the uploaded content type (such as S3 and GCS), the file is then served with the attacker-supplied content type, enabling stored XSS against users who open the file URL.

This affects the default configuration, in which authenticated users are allowed to upload files. The default GridFS/filesystem adapter sets the X-Content-Type-Options: nosniff response header, which mitigates browser rendering on that adapter, but the upload restriction itself is still bypassed. This is an incomplete-fix follow-up of GHSA-vr5f-2r24-w5hc and GHSA-7wqv-xjf3-x35v.

Patches

The file upload extension validation now also evaluates the request content type against the configured blocklist whenever the filename's extension is not a recognized type. As a result, a dangerous content type can no longer be preserved by uploading a file with a non-standard extension, and such uploads are rejected.

Workarounds

Configure fileUpload.fileExtensions as a strict allowlist of only the file extensions your application needs (for example ["^(png|jpe?g|gif|pdf)$"]) instead of relying on the default blocklist. Additionally, serve uploaded files from a separate domain than the application, so that any executed content is isolated from the application's origin.

Database specific
{
    "cwe_ids":  [
        "CWE-434"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-19T19:36:36Z",
    "nvd_published_at":  null,
    "severity":  "LOW"
}
References

Affected packages

npm / parse-server

Package

Affected ranges

Type
SEMVER
Events
Introduced
9.0.0
Fixed
9.9.1-alpha.11

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-v8x7-r927-cc93/GHSA-v8x7-r927-cc93.json"

npm / parse-server

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.6.81

Database specific

last_known_affected_version_range
"<= 8.6.80"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-v8x7-r927-cc93/GHSA-v8x7-r927-cc93.json"