{"id":"GHSA-v8x7-r927-cc93","summary":"parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist","details":"### Impact\n\nParse Server's default `fileUpload.fileExtensions` blocklist is intended to prevent uploading files that browsers render as active content (such as HTML and SVG), which can be used to perform stored cross-site scripting (XSS) attacks against other users. The blocklist could be bypassed by uploading a file whose extension is not an exact match of a blocked extension (for example a non-standard or compound extension) together with a dangerous content type. On storage adapters that persist and serve the uploaded content type (such as S3 and GCS), the file is then served with the attacker-supplied content type, enabling stored XSS against users who open the file URL.\n\nThis affects the default configuration, in which authenticated users are allowed to upload files. The default GridFS/filesystem adapter sets the `X-Content-Type-Options: nosniff` response header, which mitigates browser rendering on that adapter, but the upload restriction itself is still bypassed. This is an incomplete-fix follow-up of GHSA-vr5f-2r24-w5hc and GHSA-7wqv-xjf3-x35v.\n\n### Patches\n\nThe file upload extension validation now also evaluates the request content type against the configured blocklist whenever the filename's extension is not a recognized type. As a result, a dangerous content type can no longer be preserved by uploading a file with a non-standard extension, and such uploads are rejected.\n\n### Workarounds\n\nConfigure `fileUpload.fileExtensions` as a strict allowlist of only the file extensions your application needs (for example `[\"^(png|jpe?g|gif|pdf)$\"]`) instead of relying on the default blocklist. Additionally, serve uploaded files from a separate domain than the application, so that any executed content is isolated from the application's origin.","aliases":["BIT-parse-2026-55778","CVE-2026-55778"],"modified":"2026-07-14T16:40:35.629992595Z","published":"2026-06-19T19:36:36Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-434"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-06-19T19:36:36Z"},"references":[{"type":"WEB","url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-v8x7-r927-cc93"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/pull/10505"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/pull/10506"},{"type":"PACKAGE","url":"https://github.com/parse-community/parse-server"}],"affected":[{"package":{"name":"parse-server","ecosystem":"npm","purl":"pkg:npm/parse-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"9.0.0"},{"fixed":"9.9.1-alpha.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-v8x7-r927-cc93/GHSA-v8x7-r927-cc93.json"}},{"package":{"name":"parse-server","ecosystem":"npm","purl":"pkg:npm/parse-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"8.6.81"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 8.6.80","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-v8x7-r927-cc93/GHSA-v8x7-r927-cc93.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"}]}