CyberSec.Space Logo
CVEブラウザに戻る

CVE-2026-53724

PENDING
N/A
CVSS Severity Score
EPSS Score0.0300%
EPSS Percentile10.40th
Published2026年6月12日
Last Modified2026年6月12日

Vulnerability Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the default file upload extension blocklist can be bypassed by appending a trailing dot to a filename whose extension would otherwise be blocked (e.g. poc.svg.). The trailing dot causes the extension parser to extract an empty string, which short-circuits the blocklist check, and the attacker-controlled Content-Type is forwarded to the storage adapter unchanged. Storage adapters that persist and serve the provided Content-Type (such as S3 or GCS) then serve the file with an active type such as image/svg+xml, enabling stored XSS when a victim opens the file URL. The default GridFS adapter is not affected because it sets X-Content-Type-Options: nosniff on responses. This issue has been patched in versions 8.6.79 and 9.9.1-alpha.4.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

関連する脆弱性情報