{"id":"GHSA-9f2h-7v79-mxw3","summary":"Parse Javascript SDK vulnerable to prototype pollution in `Parse.Object` and internal APIs","details":"### Summary\n\nPrototype pollution capabilities on various APIs.\n\n### Details\n\nInjection of malicious payload allows attacker to remotely execute arbitrary code. `Parse.Object` and internal APIs are affected, specifically:\n- `ParseObject.fromJSON`\n- `ParseObject.pin`\n- `ParseObject.registerSubclass`\n- `ObjectStateMutations` (internal)\n- `encode`/`decode` (internal)\n\n### PoC\n\nDemonstrative tests added as part of the fix.\n\n### References\n\n- https://github.com/parse-community/Parse-SDK-JS/security/advisories/GHSA-9f2h-7v79-mxw3\n- Patch https://github.com/parse-community/Parse-SDK-JS/releases/tag/7.0.0-alpha.1","aliases":["CVE-2025-62374"],"modified":"2025-10-14T22:57:35.569957Z","published":"2025-10-14T22:24:10Z","database_specific":{"nvd_published_at":"2025-10-14T20:15:53Z","cwe_ids":["CWE-1321"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-10-14T22:24:10Z"},"references":[{"type":"WEB","url":"https://github.com/parse-community/Parse-SDK-JS/security/advisories/GHSA-9f2h-7v79-mxw3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62374"},{"type":"WEB","url":"https://github.com/parse-community/Parse-SDK-JS/pull/2749"},{"type":"WEB","url":"https://github.com/parse-community/Parse-SDK-JS/commit/00973987f361368659c0c4dbf669f3897520b132"},{"type":"PACKAGE","url":"https://github.com/parse-community/Parse-SDK-JS"},{"type":"WEB","url":"https://github.com/parse-community/Parse-SDK-JS/releases/tag/7.0.0-alpha.1"}],"affected":[{"package":{"name":"parse","ecosystem":"npm","purl":"pkg:npm/parse"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"7.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-9f2h-7v79-mxw3/GHSA-9f2h-7v79-mxw3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L"}]}