
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30848 is a path traversal vulnerability in Parse Server's PagesRouter static file serving route that allows unauthenticated attackers to read files outside the configured pagesPath directory. It affects Parse Server versions prior to 8.6.8 (on the 8.x branch) and versions 9.0.0 through 9.5.0-alpha.7 (on the 9.x branch). The vulnerability was published on March 7, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 3.7 (Low) and a CVSS v4.0 base score of 6.3 (Medium) (GitHub Advisory, Github Advisory).
The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). The PagesRouter performs a boundary check using a simple string prefix comparison — verifying that the resolved file path starts with the pagesPath string — without enforcing a directory separator boundary. This means an attacker can craft a request with path traversal sequences (e.g., ../) to escape the intended directory and access files in sibling directories whose names share the same prefix as the pages directory (e.g., if pagesPath is /srv/pages, a directory named /srv/pages-secret would pass the prefix check). Exploitation requires that the pages feature is enabled (pages.enableRouter: true) and that at least one sibling directory exists whose name begins with the same prefix as the configured pages directory (GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to read arbitrary files from sibling directories that share a name prefix with the configured pages directory, potentially exposing sensitive configuration files, application secrets, credentials, or other confidential data. There is no integrity or availability impact — the vulnerability is limited to unauthorized file disclosure. The scope of exposure depends on the server's directory layout and what sensitive data resides in prefix-matching sibling directories (GitHub Advisory, Github Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (Feedly). The EPSS score is approximately 0.022% (6th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires specific deployment conditions — the pages router must be enabled and a prefix-matching sibling directory must exist — which limits the attack surface (Github Advisory).
pages.enableRouter: true) by probing for the PagesRouter endpoint (typically accessible via HTTP/HTTPS on the Parse Server port).pagesPath directory name (e.g., /srv/pages, /app/pages) and identify potential sibling directories with matching prefixes (e.g., pages-config, pages-secret).GET /pages/../pages-secret/config.json.pagesPath string (not that it is strictly inside it), the traversal into a sibling directory with a matching prefix passes validation.../, %2e%2e%2f, or URL-encoded variants) in the file path parameter; requests targeting files with extensions such as .json, .env, .conf, or .key outside the expected pages directory.pagesPath that share a name prefix (e.g., pages-backup, pages-secret), particularly configuration or credential files.Upgrade Parse Server to version 8.6.8 (for the 8.x branch) or 9.5.0-alpha.8 (for the 9.x branch), which enforce a path separator boundary in the directory check to ensure resolved paths are strictly inside pagesPath. As a temporary workaround for deployments that cannot immediately upgrade, ensure no sibling directories exist alongside pagesPath whose names begin with the same prefix — for example, if pagesPath is /srv/pages, remove or rename any directories like /srv/pages-backup or /srv/pages_old. Additionally, review access logs for suspicious file access patterns that may indicate prior exploitation attempts (GitHub Advisory, Github Advisory).
The vulnerability was reported by researcher fancymalware and coordinated by mtrezza from the Parse community. The advisory was published directly by the Parse Server maintainers on GitHub with a Moderate severity rating. No significant broader media coverage or notable public researcher commentary beyond the official advisory has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."