CVE-2026-33539: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-33539 is an SQL injection vulnerability in Parse Server's PostgreSQL storage adapter that allows an attacker with master key access to execute arbitrary SQL statements against the underlying PostgreSQL database. It affects all Parse Server versions prior to 8.6.59 and versions 9.0.0 through 9.6.0-alpha.52 running on Node.js with a PostgreSQL backend; MongoDB deployments are not affected. The vulnerability was disclosed on March 21, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 8.6 (High) (GitHub Advisory).

Technical details

The root cause is improper neutralization of SQL special characters (CWE-89) in the PostgreSQL storage adapter's transformAggregateField() and distinct() functions. Field name parameters supplied to the aggregate $group._id pipeline stage and the distinct operation were passed directly into SQL queries via :raw interpolation without sanitization, allowing SQL metacharacters (e.g., double quotes, semicolons) to break out of the intended query context. The fix introduced a validateAggregateFieldName() helper enforcing the regex /^[a-zA-Z][a-zA-Z0-9_]*$/ on each field name segment, rejecting any input containing SQL-unsafe characters with a Parse.Error.INVALID_KEY_NAME error (GitHub Advisory, Fix PR #10272, Fix PR #10273).

Impact

Successful exploitation allows a Parse Server application-level administrator (master key holder) to escalate privileges to full PostgreSQL database-level access, enabling arbitrary SQL execution. This can result in complete compromise of the database — including unauthorized reading, modification, or deletion of all stored data — as well as potential creation of backdoors, disruption of database availability, or lateral movement to other systems accessible from the database host. The confidentiality, integrity, and availability of the PostgreSQL database are all fully impacted (GitHub Advisory).

Exploitability

Exploitation requires possession of the Parse Server master key, which limits the attack surface to application-level administrators. No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.046% (very low probability of near-term exploitation). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Obtain master key: Acquire the Parse Server master key through credential theft, insider access, or compromise of configuration files/environment variables where the key is stored.
  2. Identify target endpoint: Confirm the Parse Server deployment uses PostgreSQL (not MongoDB) and locate the aggregate or distinct API endpoint, typically at GET /1/aggregate/<ClassName> or using the distinct query parameter.
  3. Craft malicious aggregate payload: Send a GET request to the aggregate endpoint with a pipeline containing a $group._id field value that embeds SQL metacharacters, e.g.:
GET /1/aggregate/TestClass
Headers: X-Parse-Master-Key: <master_key>
Query: pipeline=[{"$group":{"_id":{"alias":"$playerName\" OR 1=1 --"}}}]
  1. Alternatively, inject via distinct: Send a request using the distinct parameter with a dot-notation field name containing SQL metacharacters, e.g., distinct=metadata" FROM pg_tables; --.tag.
  2. Execute arbitrary SQL: The injected metacharacters break out of the :raw SQL interpolation context in the PostgreSQL adapter, causing the database to execute attacker-controlled SQL statements — enabling data exfiltration, schema manipulation, or privilege escalation within PostgreSQL (GitHub Advisory, Fix Commit).

Indicators of compromise

  • Network: Unusual or malformed GET requests to /1/aggregate/<ClassName> endpoints containing SQL metacharacters (e.g., ", ;, ', --, OR 1=1) in pipeline or distinct query parameters; requests authenticated with the master key from unexpected IP addresses.
  • Logs: Parse Server access logs showing requests to aggregate or distinct endpoints with field names containing non-alphanumeric characters (outside [a-zA-Z0-9_.]); PostgreSQL query logs showing unexpected SQL statements such as DROP TABLE, SELECT * FROM pg_tables, or tautological conditions like OR 1=1.
  • Database: Unexpected schema changes, new database users or roles, unauthorized table reads or modifications, or anomalous queries in PostgreSQL's pg_stat_activity or query logs originating from the Parse Server database user.

Mitigation and workarounds

Upgrade Parse Server to version 8.6.59 (for the 8.x LTS line) or 9.6.0-alpha.53 or later (for the 9.x line); no configuration-based workaround exists. Additionally, restrict master key access to the minimum number of trusted administrators, implement network segmentation to limit direct PostgreSQL access, and monitor database logs for anomalous SQL query patterns. Review access logs for unauthorized or unexpected use of the master key (GitHub Advisory, Fix PR #10273).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management