CVE-2026-34532: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-34532 is a Cloud Function validator bypass vulnerability in Parse Server (open source Node.js backend) caused by prototype chain traversal. An unauthenticated attacker can bypass access control validators — including requireUser, requireMaster, and custom validation logic — by appending .prototype.constructor to a Cloud Function name in the URL. Affected versions are all Parse Server releases prior to 8.6.67 (8.x branch) and 9.0.0 through 9.7.0-alpha.10 (9.x branch). The vulnerability was disclosed on March 31, 2026, with patches released on March 28, 2026. It carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 base score of 9.1 (Critical) (GitHub Advisory).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization), stemming from an asymmetry in how the trigger store and validator store traverse the function registry. When a Cloud Function handler is declared using the function keyword, the trigger store's getStore() function in src/triggers.js resolves the handler by traversing the store object's prototype chain. However, the validator store does not mirror this traversal, so when an attacker appends .prototype.constructor to the function name in the URL (e.g., POST /1/functions/protectedFn.prototype.constructor), the handler is resolved via the prototype chain while the validator lookup returns nothing — causing all access control enforcement to be silently skipped. The fix adds a single check in getStore(): if (!store || Object.getPrototypeOf(store) !== null), which rejects any resolved store node that is not a null-prototype object, preventing prototype chain escape (GitHub Advisory, Fix Commit v8, Fix Commit v9).

Impact

Successful exploitation allows unauthenticated remote attackers to invoke any Cloud Function that is protected by validators such as requireUser, requireMaster, or custom authorization logic, effectively bypassing all authentication and authorization controls on those endpoints. This can expose sensitive backend operations and data to unauthorized callers, with high impact to both confidentiality and integrity of the vulnerable system. Availability is not directly impacted, but the ability to invoke privileged backend functions without credentials could enable data exfiltration, unauthorized data modification, or further lateral movement within the application's backend (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability requires no authentication, no user interaction, and is exploitable over the network with low attack complexity, making it highly automatable once the technique is known. The EPSS score is approximately 0.044% (0.000440), indicating a currently low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Parse Server instances (versions < 8.6.67 or 9.0.0–9.7.0-alpha.10) using tools like Shodan or Censys, searching for the Parse Server API endpoint (typically /1/functions/).
  2. Enumerate Cloud Functions: Probe the target for known or guessable Cloud Function names by sending standard POST requests to /1/functions/<name> and observing error responses (e.g., VALIDATION_ERROR indicates a protected function exists).
  3. Craft bypass request: Append .prototype.constructor to the discovered function name in the URL, e.g., POST /1/functions/protectedFn.prototype.constructor, with standard Parse headers (X-Parse-Application-Id, X-Parse-REST-API-Key) and an empty JSON body.
  4. Bypass validator: The server's getStore() traversal resolves the handler via the prototype chain while the validator store returns nothing, causing all access control checks to be skipped — the function executes without authentication.
  5. Achieve objective: The protected Cloud Function executes in the context of an unauthenticated caller, potentially returning sensitive data, performing privileged operations, or enabling further exploitation of the backend (GitHub Advisory, Fix PR v9).

Indicators of compromise

  • Network: HTTP POST requests to Parse Server endpoints matching the pattern /1/functions/<functionName>.prototype.constructor or /1/functions/<functionName>.prototype from unauthenticated clients (no valid session token or master key).
  • Logs: Parse Server access logs showing requests to Cloud Function endpoints with .prototype or .prototype.constructor in the function name path segment; successful HTTP 200 responses to such requests on unpatched servers.
  • Application Behavior: Cloud Functions returning results to callers that lack the required session token, master key, or other credentials normally enforced by validators such as requireUser or requireMaster.

Mitigation and workarounds

Upgrade Parse Server to version 8.6.67 (8.x LTS branch) or 9.7.0-alpha.11 (or the stable 9.7.0 release) to apply the patch (GitHub Advisory, Fix PR v8, Fix PR v9). As an immediate workaround for those unable to upgrade, rewrite all Cloud Function handlers using arrow functions instead of the function keyword — arrow functions do not have a prototype property and are not susceptible to this traversal. Organizations running any 8.x version below 8.6.67 or any 9.x version below 9.7.0 should treat this as a high-priority patch given the unauthenticated, network-exploitable nature of the vulnerability.

Community reactions

The advisory was published by Parse Server maintainer mtrezza and credited bugbunny-research as the reporter (GitHub Advisory). The vulnerability was noted in automated vulnerability tracking feeds and aggregators shortly after disclosure, with no significant public researcher commentary or media coverage identified beyond standard CVE distribution channels.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management