CVE-2026-30848: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-30848 is a path traversal vulnerability in Parse Server's PagesRouter static file serving route that allows unauthenticated attackers to read files outside the configured pagesPath directory. It affects Parse Server versions prior to 8.6.8 (on the 8.x branch) and versions 9.0.0 through 9.5.0-alpha.7 (on the 9.x branch). The vulnerability was published on March 7, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 3.7 (Low) and a CVSS v4.0 base score of 6.3 (Medium) (GitHub Advisory, Github Advisory).

Technical details

The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). The PagesRouter performs a boundary check using a simple string prefix comparison — verifying that the resolved file path starts with the pagesPath string — without enforcing a directory separator boundary. This means an attacker can craft a request with path traversal sequences (e.g., ../) to escape the intended directory and access files in sibling directories whose names share the same prefix as the pages directory (e.g., if pagesPath is /srv/pages, a directory named /srv/pages-secret would pass the prefix check). Exploitation requires that the pages feature is enabled (pages.enableRouter: true) and that at least one sibling directory exists whose name begins with the same prefix as the configured pages directory (GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to read arbitrary files from sibling directories that share a name prefix with the configured pages directory, potentially exposing sensitive configuration files, application secrets, credentials, or other confidential data. There is no integrity or availability impact — the vulnerability is limited to unauthorized file disclosure. The scope of exposure depends on the server's directory layout and what sensitive data resides in prefix-matching sibling directories (GitHub Advisory, Github Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (Feedly). The EPSS score is approximately 0.022% (6th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires specific deployment conditions — the pages router must be enabled and a prefix-matching sibling directory must exist — which limits the attack surface (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Parse Server instances with the pages feature enabled (pages.enableRouter: true) by probing for the PagesRouter endpoint (typically accessible via HTTP/HTTPS on the Parse Server port).
  2. Enumerate directory structure: Attempt to infer or guess the configured pagesPath directory name (e.g., /srv/pages, /app/pages) and identify potential sibling directories with matching prefixes (e.g., pages-config, pages-secret).
  3. Craft traversal request: Send an HTTP GET request to the PagesRouter static file serving route with a path traversal payload that navigates out of the pages directory and into a sibling directory, e.g.: GET /pages/../pages-secret/config.json.
  4. Bypass prefix check: Because the boundary check only verifies that the resolved path starts with the pagesPath string (not that it is strictly inside it), the traversal into a sibling directory with a matching prefix passes validation.
  5. Retrieve sensitive files: Read the response to obtain the contents of files from the sibling directory, potentially including configuration files, API keys, database credentials, or other secrets (GitHub Advisory).

Indicators of compromise

  • Network: Unusual HTTP GET requests to the Parse Server PagesRouter endpoint containing path traversal sequences (e.g., ../, %2e%2e%2f, or URL-encoded variants) in the file path parameter; requests targeting files with extensions such as .json, .env, .conf, or .key outside the expected pages directory.
  • Logs: Parse Server access logs showing requests to the pages route with traversal patterns resolving to sibling directories; HTTP 200 responses for requests to unexpected file paths that should not be publicly accessible.
  • File System: Evidence of access to files in directories adjacent to the configured pagesPath that share a name prefix (e.g., pages-backup, pages-secret), particularly configuration or credential files.

Mitigation and workarounds

Upgrade Parse Server to version 8.6.8 (for the 8.x branch) or 9.5.0-alpha.8 (for the 9.x branch), which enforce a path separator boundary in the directory check to ensure resolved paths are strictly inside pagesPath. As a temporary workaround for deployments that cannot immediately upgrade, ensure no sibling directories exist alongside pagesPath whose names begin with the same prefix — for example, if pagesPath is /srv/pages, remove or rename any directories like /srv/pages-backup or /srv/pages_old. Additionally, review access logs for suspicious file access patterns that may indicate prior exploitation attempts (GitHub Advisory, Github Advisory).

Community reactions

The vulnerability was reported by researcher fancymalware and coordinated by mtrezza from the Parse community. The advisory was published directly by the Parse Server maintainers on GitHub with a Moderate severity rating. No significant broader media coverage or notable public researcher commentary beyond the official advisory has been identified.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management