CVE-2026-33627: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-33627 is an information disclosure vulnerability in Parse Server (open source Node.js backend) where the GET /users/me endpoint returns unsanitized authentication data — including MFA TOTP secrets and recovery codes — to authenticated users. It affects all Parse Server versions prior to 8.6.61 and versions 9.0.0 through 9.6.0-alpha.54. The vulnerability was published on March 22, 2026 (GitHub Advisory) and March 24, 2026 (NVD). It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.1 (High) (GitHub Advisory).

Technical details

The root cause (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) lies in the handleMe() method of UsersRouter.js. The original implementation queried the _Session collection using master-level authentication with { include: 'user' }, causing the master context to propagate into the user data fetch and bypass auth adapter sanitization (specifically the afterFind hook). As a result, sensitive fields such as MFA TOTP secrets (authData.mfa.secret) and recovery codes (authData.mfa.recovery) were returned in the API response without being filtered. Exploitation requires only a valid session token — obtainable via normal login — and a simple GET /users/me HTTP request with the X-Parse-Session-Token header (GitHub Advisory, Fix PR #10279).

Impact

An authenticated attacker who obtains any user's session token can call GET /users/me to extract that user's raw MFA TOTP secret and recovery codes. With the TOTP secret, the attacker can generate valid one-time codes indefinitely, effectively bypassing multi-factor authentication and enabling persistent account takeover. This is a confidentiality-only impact with no direct integrity or availability consequences, but the downstream effect of MFA bypass can expose all data and functionality accessible to the compromised account (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability requires low privileges (a valid session token) and no user interaction, making it straightforward to exploit once a session token is obtained. The EPSS score is approximately 0.093%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Exploitation steps

  1. Obtain a session token: Authenticate to the target Parse Server application as any valid user (e.g., via POST /login) to receive a session token in the response.
  2. Call the /users/me endpoint: Send a GET /users/me request to the Parse Server with the session token in the X-Parse-Session-Token header:
    GET /1/users/me HTTP/1.1
    Host: <parse-server-host>
    X-Parse-Application-Id: <app-id>
    X-Parse-Session-Token: <session-token>
  3. Extract MFA secrets from response: In vulnerable versions, the JSON response includes unsanitized authData, e.g.:
    { "authData": { "mfa": { "secret": "<BASE32_TOTP_SECRET>", "recovery": ["<code1>", "<code2>"] } } }
  4. Generate TOTP codes: Use the extracted secret with any TOTP library (e.g., otpauth in Node.js or Google Authenticator) to generate valid one-time codes indefinitely.
  5. Bypass MFA and take over account: Use the generated TOTP codes to authenticate as the victim user, bypassing MFA protections and gaining full account access (GitHub Advisory, Fix Commit).

Indicators of compromise

  • Network: Unusual or repeated GET /1/users/me requests from IP addresses not associated with the legitimate user's normal activity; requests using session tokens belonging to other users.
  • Logs: Parse Server access logs showing GET /users/me requests returning authData fields containing secret or recovery keys (visible in debug/verbose logging); requests from unexpected geographic locations or user agents.
  • Application Behavior: Successful MFA logins from devices or locations not previously associated with a user account, particularly shortly after a GET /users/me request from an anomalous source.
  • Account Activity: MFA bypass events or logins using recovery codes that the legitimate user did not initiate.

Mitigation and workarounds

Upgrade Parse Server immediately to version 8.6.61 (for 8.x installations) or 9.6.0-alpha.55 or later (for 9.x installations). The fix refactors handleMe() to perform a two-step fetch: the _Session is queried with master key (without including user data), and the user is then re-fetched separately using the caller's own authentication context, ensuring all security layers (protectedFields, CLP, auth adapter afterFind) apply correctly. There is no known workaround — patching is the only remediation. Additionally, administrators should rotate MFA secrets and recovery codes for any users who may have been affected, and implement monitoring for anomalous GET /users/me requests (GitHub Advisory, Fix PR #10278, Fix PR #10279).

Community reactions

The vulnerability was discovered and reported by Parse Server maintainer mtrezza, who also authored the fix. The advisory was published quietly alongside a large batch of security fixes included in the Parse Server 9.6.0 stable release, which addressed over 50 security issues simultaneously. No significant independent researcher commentary or broad media coverage has been identified beyond standard CVE tracking and aggregator sites.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management