CVE-2026-33421: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-33421 is an incorrect authorization vulnerability in Parse Server's LiveQuery WebSocket interface that allows authenticated users to bypass Class-Level Permission (CLP) pointer permissions (readUserFields and pointerFields). Any authenticated user can subscribe to LiveQuery events and receive real-time updates for all objects in pointer-permission-protected classes, regardless of whether those objects' pointer fields reference the subscribing user. The vulnerability affects Parse Server (npm) versions < 8.6.53 and >= 9.0.0, < 9.6.0-alpha.42 running on Node.js. It was published on March 20, 2026, and assigned a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 7.1 (High) (GitHub Advisory, Parse Server Advisory).

Technical details

The root cause is CWE-863 (Incorrect Authorization): the LiveQuery server's existing CLP check deferred pointer permission evaluation by design, but never subsequently enforced it, meaning the check was effectively skipped for WebSocket-based subscriptions. When an object is created or updated, the LiveQuery server broadcasts events to all subscribers without verifying whether the subscribing user is referenced by the configured pointer fields (readUserFields or pointerFields) on that object. The attack vector is network-based, requires low privileges (a valid authenticated session), and no user interaction. The fix, applied in src/LiveQuery/ParseLiveQueryServer.ts, adds a post-check in _matchesCLP that resolves the subscriber's user ID from their session token and verifies that at least one configured pointer field on the object references that user before delivering the event; non-matching events are silently skipped, consistent with ACL mismatch handling (GitHub Advisory, Fix Commit v9, Fix Commit v8).

Impact

Exploitation results in a high-confidentiality-impact breach with no integrity or availability impact. An authenticated attacker can receive real-time data updates for all objects in any class protected by CLP pointer permissions — data that is correctly restricted when accessed via the REST API. This could expose sensitive user-specific data (e.g., private messages, personal documents, or records with restricted ownership fields) to any authenticated user in the application, potentially affecting all users' private data across all pointer-permission-protected classes (GitHub Advisory, Parse Server Advisory).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.01% (2nd percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only a valid authenticated account, making it accessible to any registered user of an affected Parse Server application (GitHub Advisory, Feedly).

Exploitation steps

  1. Obtain authentication credentials: Register or obtain a valid user account on the target Parse Server application. Any authenticated user account is sufficient — no elevated privileges are required.
  2. Identify LiveQuery-enabled classes: Enumerate or infer class names that have LiveQuery enabled (configured in the server's liveQuery.classNames option). These are often the same classes used by the application's real-time features.
  3. Establish a WebSocket connection: Connect to the Parse Server LiveQuery WebSocket endpoint (typically ws://<host>/1 or wss://<host>/1) using the Parse SDK or a raw WebSocket client, authenticating with the obtained session token.
  4. Subscribe to a target class: Send a LiveQuery subscription message for the target class (e.g., PrivateMessage) without any query filters. On unpatched servers, the CLP pointer permission check is not enforced, so the subscription is accepted regardless of the class's readUserFields or pointerFields configuration.
  5. Receive unauthorized real-time events: As other users create or update objects in the protected class, the attacker's subscription receives create, update, enter, and leave events — including full object data — for objects whose pointer fields do not reference the attacker, exposing data that the REST API would correctly deny (GitHub Advisory, Parse Server Advisory).

Indicators of compromise

  • Network: Unusual or high-volume WebSocket connections to the Parse Server LiveQuery endpoint (ws:// or wss://) from user accounts that do not normally use real-time features; subscriptions to classes containing sensitive data from accounts that should not have access.
  • Logs: Parse Server access logs showing WebSocket upgrade requests (GET /1 with Upgrade: websocket) from unexpected client IPs or user accounts; LiveQuery subscription messages for pointer-permission-protected class names from users not referenced in those classes' pointer fields.
  • Application Behavior: Authenticated users receiving LiveQuery events for objects they do not own or are not referenced in (detectable via application-level audit logging if implemented); unexpected data access patterns inconsistent with normal user activity.

Mitigation and workarounds

Upgrade immediately to one of the patched versions:

  • Parse Server 8.6.53 or later (for the v8 branch)
  • Parse Server 9.6.0-alpha.42 or later (for the v9 alpha branch), or the stable 9.6.0 release

Patches are available via npm: npm install parse-server@8.6.53 or npm install parse-server@9.6.0.

Workaround (if immediate patching is not possible): Replace or supplement CLP pointer permissions with object-level ACLs on individual objects. ACLs are correctly enforced by the LiveQuery server and will prevent unauthorized event delivery. Additionally, consider implementing network-level restrictions on LiveQuery WebSocket access and reviewing access logs for unusual subscription patterns (GitHub Advisory, Parse Server Advisory).

Community reactions

The vulnerability was reported and coordinated by Parse Server maintainer mtrezza, who also authored the fix. The advisory was published through GitHub's security advisory process (GHSA-fph2-r4qg-9576) on March 20, 2026, and the fix was merged and released the same day. No significant external researcher commentary or broad media coverage has been identified beyond standard vulnerability database entries (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management