CVE-2026-32878: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-32878 is a prototype pollution vulnerability in Parse Server (an open-source Node.js backend) that allows attackers to bypass the default request keyword denylist and class-level permissions for adding fields, resulting in schema poisoning. It affects all versions of parse-server (npm) prior to 8.6.44 and versions >= 9.0.0 prior to 9.6.0-alpha.20. The vulnerability was published on March 16, 2026, and patched on March 14, 2026 (with public disclosure on March 16–18, 2026). It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 5.3 (Medium) (GitHub Advisory, Parse Server Advisory).

Technical details

The root cause is classified as CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes — Prototype Pollution). Parse Server's security pipeline performs a deep copy of incoming request data before running its keyword denylist check; the third-party deep copy library strips __proto__ properties as a normal part of its cloning behavior, meaning the denylist check never inspects the prohibited key. An attacker with low-level authenticated access can craft a request containing a __proto__-based payload that survives the deep copy step and injects arbitrary fields into class schemas that have field addition locked down via class-level permissions (CLP). The resulting schema type conflicts are permanent and cannot be resolved even using the master key, making this a destructive integrity attack (GitHub Advisory, Parse Server Advisory). The fix replaced the vulnerable third-party deepcopy library with a built-in structuredClone-based mechanism (with JSON fallback) that handles prototype properties safely (PR #10200, PR #10201).

Impact

Successful exploitation allows an attacker to inject unauthorized fields into locked-down class schemas, bypassing both the request keyword denylist and class-level permissions for field addition. The injected schema type conflicts are permanent and irrecoverable — even the master key cannot resolve them — effectively causing lasting data integrity damage and potential denial of service for affected classes. There is no confidentiality or availability impact in the direct attack path, but the permanent corruption of schema definitions can disrupt application functionality for all users of the affected Parse Server instance (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-32878. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.044% (4th percentile), indicating a low near-term probability of exploitation. Exploitation requires low-level authenticated access (a valid Parse Server account), reducing the attack surface compared to fully unauthenticated vulnerabilities (GitHub Advisory, Parse Server Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Parse Server instance running a vulnerable version (< 8.6.44 or >= 9.0.0 and < 9.6.0-alpha.20) by checking npm package metadata or server response headers.
  2. Obtain credentials: Register or obtain a low-privilege Parse Server account (self-service registration may suffice if enabled).
  3. Craft malicious request: Construct an HTTP request (REST or GraphQL) targeting a class with field addition locked down via CLP. Include a __proto__-polluted payload in the request body, e.g., embedding a field definition under __proto__ to inject a new field type into the class schema.
  4. Bypass denylist: The deep copy step in Parse Server's request pipeline strips the __proto__ key from the object's own properties but propagates its values onto the prototype, causing the subsequent denylist check to miss the prohibited keyword.
  5. Achieve schema poisoning: The injected field is written into the class schema, creating a permanent type conflict that cannot be removed even with the master key, corrupting the schema for all users of that class (GitHub Advisory, Parse Server Advisory).

Indicators of compromise

  • Network: Unusual HTTP POST/PUT requests to Parse Server class endpoints containing __proto__ or prototype-polluting keys in the JSON body; requests from authenticated low-privilege accounts attempting to modify schema-locked classes.
  • Logs: Parse Server access logs showing requests to class or schema endpoints with unexpected field names or type definitions; error logs indicating schema type conflicts on classes that should be locked.
  • Application State: Unexpected fields appearing in class schemas that were previously locked against field addition; schema type conflicts that cannot be resolved via the Parse Server dashboard or master key API calls.

Mitigation and workarounds

Upgrade Parse Server to version 8.6.44 (LTS branch) or 9.6.0-alpha.20 (or later stable 9.6.0) to receive the fix. The patch replaces the vulnerable third-party deepcopy library with a built-in structuredClone-based deep clone mechanism that correctly preserves prototype property visibility for the denylist check. No configuration-based workarounds are available — upgrading is the only remediation (GitHub Advisory, PR #10200, PR #10201).

Community reactions

The vulnerability was reported and coordinated by Parse Server maintainer mtrezza, who also authored the fix. Social media activity was limited to automated security feed posts on Mastodon (e.g., @thehackerwire and @RedPacketSecurity) shortly after public disclosure. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability aggregator listings (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management