
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33163 is an information disclosure vulnerability in Parse Server (an open-source Node.js backend) where the LiveQuery server leaks protected fields and authData to all subscribers of a class when a Parse.Cloud.afterLiveQueryEvent trigger is registered. It affects Parse Server versions >= 9.0.0 and < 9.6.0-alpha.35, as well as all versions < 8.6.50. The vulnerability was published on March 17, 2026, with patches released the same day. It carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 8.2 (High) (Github Advisory, Parse Server Advisory).
The root cause is a reference detachment bug (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) in src/LiveQuery/ParseLiveQueryServer.ts. When an afterLiveQueryEvent trigger is registered, the LiveQuery server converts the event object to a Parse.Object for the trigger, then creates a new JSON copy via toJSONwithObjects(). The sensitive data filter (_filterSensitiveData) was applied to the Parse.Object reference, but the unfiltered JSON copy — not the filtered reference — was sent to clients. The fix in PRs #10232 (v9) and #10233 (v8) ensures the JSON copy is assigned back to the response object before filtering, so the filter operates on the actual data transmitted to clients (Parse Server Advisory, PR #10232, PR #10233).
Any user with sufficient Class-Level Permissions (CLP) to subscribe to an affected class can receive protected field data belonging to other users across all LiveQuery event types (create, update, delete, enter, leave). Exposed data includes fields configured as protected via protectedFields in CLP settings, sensitive personal information, and OAuth tokens from third-party authentication providers such as Google, Facebook, or Apple. There is no integrity or availability impact, but the confidentiality breach could enable account takeover via stolen OAuth tokens or facilitate targeted attacks using leaked personal data (Github Advisory, Parse Server Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.038% (12th percentile), indicating a low near-term exploitation probability. Exploitation requires that the target Parse Server deployment has at least one Parse.Cloud.afterLiveQueryEvent trigger registered and that the attacker has CLP permissions sufficient to subscribe to the affected class — which in some configurations may include unauthenticated users (Github Advisory).
Parse.Cloud.afterLiveQueryEvent triggers registered for one or more classes.wss://<host>/) using the Parse SDK or a raw WebSocket client.afterLiveQueryEvent trigger registered, e.g., {"op": "subscribe", "requestId": 1, "query": {"className": "TargetClass"}}.protectedFields and authData (OAuth tokens) — directly to the subscriber due to the reference detachment bug.wss://<host>/) from unfamiliar IP addresses or at abnormal times; high volume of LiveQuery subscription requests for sensitive classes.afterLiveQueryEvent triggers from low-privilege or unauthenticated users; repeated subscriptions to the same class from a single client.Upgrade Parse Server to version 8.6.50 (LTS branch) or 9.6.0-alpha.35 (or later stable 9.6.0) to apply the fix (PR #10232, PR #10233). As an immediate workaround prior to patching, remove all Parse.Cloud.afterLiveQueryEvent trigger registrations — without an afterEvent trigger, the reference detachment does not occur and protected fields are correctly filtered. Additionally, review and tighten Class-Level Permissions (CLP) to restrict LiveQuery subscription access to only authorized users (Parse Server Advisory).
The vulnerability was discovered and reported by Parse Server maintainer mtrezza, who also authored both fix pull requests. The advisory was published simultaneously with the patches on March 17, 2026, following responsible disclosure practices. No significant external researcher commentary or broad media coverage has been identified beyond standard vulnerability database aggregation (Parse Server Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."