CVE-2026-31875: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-31875 is a logic flaw in Parse Server's MFA recovery code handling, where TOTP-based recovery codes are not invalidated after use, allowing unlimited reuse. It affects Parse Server (npm) versions < 8.6.33 and >= 9.0.0 < 9.6.0-alpha.7 for Node.js. The vulnerability was disclosed on March 10, 2026, by researcher 0xkakash1 and coordinated by mtrezza. It carries a CVSS v4 base score of 8.2 (High) and a CVSS v3.1 base score of 5.9 (Medium) (GitHub Advisory, Parse Server Advisory).

Technical details

The root cause is classified as CWE-672 (Operation on a Resource after Expiration or Release): Parse Server generates two single-use recovery codes when TOTP-based MFA is enabled, but fails to remove a recovery code from the stored list after it is successfully used for authentication. As a result, the same code remains valid indefinitely and can be submitted repeatedly via the network authentication endpoint without any additional privileges or user interaction. The fix, applied in versions 8.6.33 and 9.6.0-alpha.7, ensures each recovery code is deleted from the stored list immediately after a successful login (GitHub Advisory, Parse Server Advisory).

Impact

Successful exploitation allows an attacker who has obtained a single MFA recovery code to authenticate repeatedly as the affected user without the code ever being invalidated, effectively bypassing the MFA protection entirely. The primary impact is a high confidentiality risk — the attacker gains persistent, unauthorized access to the user's account and all data accessible through it. Integrity and availability of the system are not directly impacted by this vulnerability, but persistent unauthorized access could enable further actions such as data exfiltration or account takeover (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.139% (34th percentile), indicating a low near-term exploitation probability. Exploitation requires the attacker to first obtain a valid recovery code through phishing, credential theft, or other means, which raises the practical attack complexity (GitHub Advisory).

Exploitation steps

  1. Obtain a recovery code: Acquire a valid MFA recovery code for a target Parse Server user account through phishing, social engineering, database access, or interception of the code during initial MFA setup.
  2. Identify the target endpoint: Locate the Parse Server authentication API endpoint (e.g., /1/login or equivalent) on the target deployment.
  3. Authenticate using the recovery code: Submit the user's username/email, password, and the obtained recovery code in place of a TOTP token to the Parse Server login endpoint.
  4. Verify persistent access: Confirm that the same recovery code can be reused in subsequent authentication requests without being invalidated, providing persistent account access.
  5. Exploit account access: Use the authenticated session to access, exfiltrate, or manipulate user data and resources available to the compromised account (GitHub Advisory, Parse Server Advisory).

Indicators of compromise

  • Logs: Authentication logs showing repeated successful logins for the same user account using a recovery code (rather than a TOTP token), especially from different IP addresses or at unusual times.
  • Logs: Multiple successful MFA recovery code authentication events for the same user without any corresponding recovery code regeneration event.
  • Network: Repeated POST requests to the Parse Server login endpoint from varying source IPs for the same user account, with recovery code parameters present in the request body.
  • Application: Absence of recovery code invalidation or deletion events in the Parse Server database after successful recovery code logins (observable via database audit logs if enabled).

Mitigation and workarounds

Parse Server has released patched versions 8.6.33 (for the 8.x branch) and 9.6.0-alpha.7 (for the 9.x alpha branch), both published on March 10, 2026. There is no known configuration-based workaround — upgrading to a patched version is the only remediation. After patching, administrators should audit authentication logs for suspicious recovery code reuse, revoke and regenerate all existing MFA recovery codes for affected users, and monitor for anomalous login patterns (Parse Server 8.6.33, Parse Server 9.6.0-alpha.7).

Community reactions

The vulnerability was reported by security researcher 0xkakash1 and coordinated by Parse Server maintainer mtrezza, with the advisory published directly through GitHub's security advisory process. No significant broader media coverage or notable community commentary beyond the advisory itself has been identified at this time (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management