CVE-2026-31840: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-31840 is a critical SQL injection vulnerability in Parse Server (npm package parse-server by Parse Platform) that allows unauthenticated remote attackers to inject arbitrary SQL into a PostgreSQL database via improperly escaped dot-notation field names in query parameters. The vulnerability was published on March 10, 2026, and affects all Parse Server versions before 8.6.28 and versions 9.0.0 through 9.6.0-alpha.1 (i.e., before 9.6.0-alpha.2). It exclusively impacts deployments backed by a PostgreSQL database; MongoDB-backed deployments are not affected. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory, Parse Server Advisory).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), specifically an insufficient escaping of sub-field values when dot-notation field names are processed in PostgreSQL query generation. When Parse Server constructs SQL queries using dot-notation (e.g., object.subfield), it fails to properly escape special characters in the sub-field portion, allowing an attacker to break out of the intended SQL context. The injection is triggerable via the sort, distinct, and where query parameters in Parse Server's REST API or SDK query interface — all without requiring authentication or user interaction. The fix, applied in versions 8.6.28 and 9.6.0-alpha.2, escapes characters in dot-notation sub-field values that could allow a SQL breakout (GitHub Advisory, Parse Server Advisory).

Impact

Successful exploitation grants an unauthenticated attacker full control over the PostgreSQL database backing the Parse Server instance, with high impact to confidentiality, integrity, and availability. An attacker could exfiltrate all stored application data (user records, credentials, application state), modify or delete database records, and potentially disrupt service availability through destructive SQL operations. Depending on PostgreSQL configuration and privileges granted to the Parse Server database user, exploitation could also enable OS-level command execution via PostgreSQL extensions (e.g., COPY TO/FROM PROGRAM), enabling lateral movement beyond the database (GitHub Advisory, Feedly).

Exploitability

As of the time of reporting, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability requires no authentication, no user interaction, and no special preconditions beyond the target running Parse Server with a PostgreSQL backend, making it highly automatable if a PoC were to emerge. The EPSS score is approximately 0.045% (22nd percentile), indicating a currently low but non-negligible probability of exploitation within 30 days (GitHub Advisory). No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Parse Server instances using PostgreSQL as the database backend. Shodan or Censys queries for Parse Server API endpoints (e.g., /parse/classes/) can help enumerate targets. Confirm the backend is PostgreSQL by observing error messages or response behavior.
  2. Identify vulnerable version: Confirm the Parse Server version is below 8.6.28 (for the 8.x branch) or between 9.0.0 and 9.6.0-alpha.1 (for the 9.x branch) via version disclosure in API responses or package metadata.
  3. Craft malicious query parameter: Construct an HTTP request to the Parse Server REST API (e.g., GET /parse/classes/SomeClass) that includes a sort (or distinct or where) query parameter using a dot-notation field name with embedded SQL injection payload in the sub-field portion. For example: ?order=field.sub'-- or a more complex payload designed to break out of the SQL string context.
  4. Inject SQL payload: Send the crafted request to the Parse Server endpoint. The improperly escaped sub-field value is interpolated directly into the PostgreSQL query, allowing arbitrary SQL execution (e.g., UNION SELECT, time-based blind injection, or stacked queries depending on context).
  5. Exfiltrate or manipulate data: Use the SQL injection to dump database tables, extract credentials or sensitive records, modify data, or (if PostgreSQL superuser privileges are available) execute OS commands via COPY TO PROGRAM for further system compromise (GitHub Advisory, Parse Server Advisory).

Indicators of compromise

  • Network: Unusual or malformed HTTP requests to Parse Server API endpoints (e.g., /parse/classes/*) containing order, sort, distinct, or where parameters with SQL metacharacters (', --, ;, UNION, SELECT) in dot-notation field values; high volume of query requests from a single IP targeting these parameters.
  • Logs: Parse Server application logs showing SQL errors or unexpected query structures from PostgreSQL (e.g., syntax errors referencing dot-notation fields); PostgreSQL logs (pg_log) containing malformed or anomalous SQL statements originating from the Parse Server database user.
  • Database: Unexpected new database users, modified table schemas, or unauthorized data exports; evidence of COPY TO PROGRAM or pg_read_file calls in PostgreSQL audit logs if superuser access was achieved.
  • Process: Unexpected child processes spawned by the PostgreSQL process (e.g., shell commands) if OS-level exploitation was attempted via PostgreSQL extensions.

Mitigation and workarounds

Parse Platform has released patched versions addressing this vulnerability: Parse Server 8.6.28 and Parse Server 9.6.0-alpha.2, both released on March 9–10, 2026. Administrators should upgrade immediately to one of these versions (Parse Server 8.6.28 Release, Parse Server 9.6.0-alpha.2 Release). There is no known workaround — the vendor explicitly states no workaround exists, so patching is the only remediation (GitHub Advisory). As interim measures until patching is complete, operators should implement network-level access controls to restrict Parse Server API access to trusted clients only, and enable PostgreSQL query logging to monitor for anomalous SQL patterns.

Community reactions

The vulnerability was reported and coordinated by mtrezza, a maintainer of the parse-community/parse-server project, who also served as the coordinator for the advisory (Parse Server Advisory). The advisory was published directly by the Parse Platform maintainers on March 10, 2026, with patches released simultaneously. No significant broader media coverage or notable external researcher commentary has been identified beyond standard CVE aggregator coverage.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management