{"id":"GHSA-jhgf-2h8h-ggxv","summary":"Parse Server has a Cross-Site Scripting (XSS) vulnerability via Unescaped Mustache Template Variables","details":"## Impact\n\nA Reflected Cross-Site Scripting (XSS) vulnerability exists in Parse Server's password reset and email verification HTML pages.\n\n## Patches\n\nThe patch escapes user controlled values that are inserted into the HTML pages.\n\n## Workarounds\n\nNone.\n\n## Resources\n\n- https://github.com/parse-community/parse-server/security/advisories/GHSA-jhgf-2h8h-ggxv\n- https://github.com/parse-community/parse-server/pull/9985\n- https://github.com/parse-community/parse-server/pull/9986","aliases":["BIT-parse-2025-68115","CVE-2025-68115"],"modified":"2025-12-18T12:25:58.781785Z","published":"2025-12-16T19:36:37Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-12-16T19:36:37Z","nvd_published_at":"2025-12-16T01:15:53Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-jhgf-2h8h-ggxv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68115"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/pull/9985"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/pull/9986"},{"type":"PACKAGE","url":"https://github.com/parse-community/parse-server"}],"affected":[{"package":{"name":"parse-server","ecosystem":"npm","purl":"pkg:npm/parse-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"8.6.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-jhgf-2h8h-ggxv/GHSA-jhgf-2h8h-ggxv.json"}},{"package":{"name":"parse-server","ecosystem":"npm","purl":"pkg:npm/parse-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"9.0.0"},{"fixed":"9.1.0-alpha.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-jhgf-2h8h-ggxv/GHSA-jhgf-2h8h-ggxv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"}]}