CVE-2026-30848Disclosure(parseplatform / parse-server)

LOWCVSS 3.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.8 and 9.5.0-alpha.8, the PagesRouter static file serving route is vulnerable to a path traversal attack that allows unauthenticated reading of files outside the configured pagesPath directory. The boundary check uses a string prefix comparison without enforcing a directory separator boundary. An attacker can use path traversal sequences to access files in sibling directories whose names share the same prefix as the pages directory (e.g. pages-secret starts with pages). This issue has been patched in versions 8.6.8 and 9.5.0-alpha.8.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-07); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-07: 2Mentions · 2026-03-09: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-09: 103-0703-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-072
Disclosure2
2026-03-091
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 Parse Server, Path Traversal, #CVE-2026-30848 (Medium) https://dailycve.com/parse-server-path-traversal-cve-2026-30848-medium/

    Post summary

    The post announces a medium‑severity path traversal vulnerability (CVE‑2026‑30848) in Parse Server, linking to an external article for details.

    0000022
    166 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30848 Path Traversal Vulnerability in Parse Server Allows Unauthenticated File Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30848

    Post summary

    The text announces a path traversal flaw in Parse Server that permits unauthenticated file access, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000054
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30848 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.8 and 9.5.0-alpha.8, the PagesRouter sta… https://www.cve.org/CVERecord?id=CVE-2026-30848

    Post summary

    The message announces the existence of CVE-2026-30848 for Parse Server, noting affected versions, but provides no exploit details, patch information, or evidence of active use.

    0000083
    56.6K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-

Explore more