CVE-2026-33163: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-33163 is an information disclosure vulnerability in Parse Server (an open-source Node.js backend) where the LiveQuery server leaks protected fields and authData to all subscribers of a class when a Parse.Cloud.afterLiveQueryEvent trigger is registered. It affects Parse Server versions >= 9.0.0 and < 9.6.0-alpha.35, as well as all versions < 8.6.50. The vulnerability was published on March 17, 2026, with patches released the same day. It carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 8.2 (High) (Github Advisory, Parse Server Advisory).

Technical details

The root cause is a reference detachment bug (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) in src/LiveQuery/ParseLiveQueryServer.ts. When an afterLiveQueryEvent trigger is registered, the LiveQuery server converts the event object to a Parse.Object for the trigger, then creates a new JSON copy via toJSONwithObjects(). The sensitive data filter (_filterSensitiveData) was applied to the Parse.Object reference, but the unfiltered JSON copy — not the filtered reference — was sent to clients. The fix in PRs #10232 (v9) and #10233 (v8) ensures the JSON copy is assigned back to the response object before filtering, so the filter operates on the actual data transmitted to clients (Parse Server Advisory, PR #10232, PR #10233).

Impact

Any user with sufficient Class-Level Permissions (CLP) to subscribe to an affected class can receive protected field data belonging to other users across all LiveQuery event types (create, update, delete, enter, leave). Exposed data includes fields configured as protected via protectedFields in CLP settings, sensitive personal information, and OAuth tokens from third-party authentication providers such as Google, Facebook, or Apple. There is no integrity or availability impact, but the confidentiality breach could enable account takeover via stolen OAuth tokens or facilitate targeted attacks using leaked personal data (Github Advisory, Parse Server Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.038% (12th percentile), indicating a low near-term exploitation probability. Exploitation requires that the target Parse Server deployment has at least one Parse.Cloud.afterLiveQueryEvent trigger registered and that the attacker has CLP permissions sufficient to subscribe to the affected class — which in some configurations may include unauthenticated users (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Parse Server deployment running a vulnerable version (< 8.6.50 or >= 9.0.0 and < 9.6.0-alpha.35) that has Parse.Cloud.afterLiveQueryEvent triggers registered for one or more classes.
  2. Obtain subscription access: Acquire credentials or confirm that the target class allows unauthenticated or low-privilege subscriptions via its Class-Level Permissions (CLP) settings.
  3. Establish a LiveQuery WebSocket connection: Connect to the Parse Server LiveQuery endpoint (typically wss://<host>/) using the Parse SDK or a raw WebSocket client.
  4. Subscribe to the target class: Send a LiveQuery subscription message for the class that has an afterLiveQueryEvent trigger registered, e.g., {"op": "subscribe", "requestId": 1, "query": {"className": "TargetClass"}}.
  5. Receive unfiltered event payloads: When any LiveQuery event (create, update, delete, enter, leave) fires on the subscribed class, the server sends the unfiltered JSON payload — including protectedFields and authData (OAuth tokens) — directly to the subscriber due to the reference detachment bug.
  6. Extract sensitive data: Parse the received event payloads to extract protected field values and OAuth tokens belonging to other users, which can be used for account takeover or further attacks (Parse Server Advisory, Github Advisory).

Indicators of compromise

  • Network: Unusual or unexpected WebSocket connections to the Parse Server LiveQuery endpoint (wss://<host>/) from unfamiliar IP addresses or at abnormal times; high volume of LiveQuery subscription requests for sensitive classes.
  • Logs: Parse Server access logs showing LiveQuery subscription events for classes with afterLiveQueryEvent triggers from low-privilege or unauthenticated users; repeated subscriptions to the same class from a single client.
  • Application Behavior: Evidence of OAuth token reuse from unexpected IP addresses or user agents following LiveQuery activity, suggesting harvested tokens are being used for account access.

Mitigation and workarounds

Upgrade Parse Server to version 8.6.50 (LTS branch) or 9.6.0-alpha.35 (or later stable 9.6.0) to apply the fix (PR #10232, PR #10233). As an immediate workaround prior to patching, remove all Parse.Cloud.afterLiveQueryEvent trigger registrations — without an afterEvent trigger, the reference detachment does not occur and protected fields are correctly filtered. Additionally, review and tighten Class-Level Permissions (CLP) to restrict LiveQuery subscription access to only authorized users (Parse Server Advisory).

Community reactions

The vulnerability was discovered and reported by Parse Server maintainer mtrezza, who also authored both fix pull requests. The advisory was published simultaneously with the patches on March 17, 2026, following responsible disclosure practices. No significant external researcher commentary or broad media coverage has been identified beyond standard vulnerability database aggregation (Parse Server Advisory).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management