CVE-2026-61448Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension is not recognized by the mime package, Parse Server preserves the client-supplied Content-Type. A malformed Content-Type that is not a valid type/subtype media type (e.g., 'image', 'image/', or 'image//svg+xml') bypasses the fileUpload.fileExtensions blocklist and is stored unchanged. On storage adapters that persist and serve the uploaded Content-Type (such as Amazon S3, Google Cloud Storage, or Azure Blob Storage), a browser cannot parse the malformed value and falls back to MIME-sniffing; a file whose body begins with HTML is rendered as HTML, executing embedded script in the application's origin against other users who open the file URL. The default GridFS storage adapter is not affected. Fixed in 9.10.0-alpha.2 and 8.6.84.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-07-11); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-07-11: 3Mentions · 2026-07-12: 1Technical Details · 2026-07-11: 2Technical Details · 2026-07-12: 107-1107-12
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-113
Disclosure2General1
2026-07-121
Disclosure1
Full discourse4 posts
  • Abdullah Kareem@CyberKareem
    Disclosure

    New CVE in Parse Server CVE-2026-61448; which is affected by a stored cross-site scripting (XSS) vulnerability in versions &gt;= 9.0.0, &lt; 9.10.0-alpha.2 and &lt;= 8.6.83. #CVE #research #infosec https://t.co/olvalFAbyc

    Post summary

    A new CVE (CVE-2026-61448) affecting Parse Server versions 9.0.0–9.10.0‑alpha.2 and <=8.6.83 was disclosed, highlighting a stored XSS vulnerability.

    0000074
    235 followersView on X
  • MalwareObserver@MalwareObserver
    General

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-61448](https://github.com/parse-community/parse-server/security/advisories/GHSA-r899-h6... https://github.com/parse-community/parse-server/security/advisories/GHSA-r899-h629-j84r #Vulnerability #CVE #ZeroDay

    Post summary

    The post announces CVE‑2026‑61448 and links to a GitHub advisory, but offers no details on exploitation, PoC, patch, or technical specifics.

    0000038
    10 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-61448 Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions &gt;= 9.0.0, &lt; 9.10.0-alpha.2 and &lt;= 8.6.83. When an uploaded file's extension … https://www.cve.org/CVERecord?id=CVE-2026-61448 ----- Traducción: CVE-2026-61448 Par… http://infoflow.cloud`

    Post summary

    The post announces that Parse Server versions 9.0.0‑9.10.0‑alpha.2 and all 8.x up to 8.6.83 contain a stored XSS flaw identified as CVE-2026-61448.

    0000033
    92 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-61448 Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions &gt;= 9.0.0, &lt; 9.10.0-alpha.2 and &lt;= 8.6.83. When an uploaded file's extension … https://www.cve.org/CVERecord?id=CVE-2026-61448

    Post summary

    The text discloses a stored XSS vulnerability in Parse Server (CVE-2026-61448) with affected version ranges, without any PoC, exploit, patch, or active exploitation details.

    00000608
    57.8K followersView on X

Explore more