CVE-2025-53364 – Parse Server GraphQL API Unauthenticated Schema Introspection

The following table lists the changes that have been made to the
CVE-2025-53364 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jul. 10, 2025

    Action Type Old Value New Value
    Added Description Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.0 and before 7.5.3 and 8.2.2, the Parse Server GraphQL API previously allowed public access to the GraphQL schema without requiring a session token or the master key. While schema introspection reveals only metadata and not actual data, this metadata can still expand the potential attack surface. This vulnerability is fixed in 7.5.3 and 8.2.2.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    Added CWE CWE-497
    Added Reference https://github.com/parse-community/parse-server/pull/9819
    Added Reference https://github.com/parse-community/parse-server/pull/9820
    Added Reference https://github.com/parse-community/parse-server/security/advisories/GHSA-48q3-prgv-gm4w
Share the Post:

Related Posts