Vulnerability GHSA-7wqv-xjf3-x35v

Low Risk
LOW RISK
CVSS Score: 3.0
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
3 months ago
June 19, 2026 at 07:35 PM UTC
parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist
1.0.0 - 8.6.78 and 9.0.0 - 9.9.1-alpha.3
1.0.0 - 8.6.78 and 9.0.0 - 9.9.1-alpha.3

Summary

parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist

Details

Impact

The default file upload extension blocklist can be bypassed by appending a trailing dot to a filename whose extension would otherwise be blocked (e.g. poc.svg.). The trailing dot causes the extension parser to extract an empty string, which short-circuits the blocklist check, and the attacker-controlled Content-Type is forwarded to the storage adapter unchanged. Storage adapters that persist and serve the provided Content-Type (such as S3 or GCS) then serve the file with an active type such as image/svg+xml, enabling stored XSS when a victim opens the file URL. The default GridFS adapter is not affected because it sets X-Content-Type-Options: nosniff on responses.

Patches

A filename ending in a dot is now treated as extensionless. When the parser produces an empty extension, the request handler falls back to validating the Content-Type subtype against the configured extension blocklist, matching the path that already catches truly extensionless uploads with a dangerous Content-Type. This is a follow-up to the previous fix GHSA-vr5f-2r24-w5hc.

Workarounds

Configure the storage adapter or CDN to derive Content-Type from the filename extension instead of using the stored Content-Type, or replace the default blocklist with an explicit allowlist of needed file extensions.

Impacted packages

Timeline

Published
3 months ago
June 19, 2026 at 07:35 PM UTC
Fixed (9.9.1-alpha.4)
3 months ago
June 01, 2026 at 09:37 PM UTC
Fixed (8.6.79)
3 months ago
June 01, 2026 at 09:38 PM UTC
Last Modified
3 months ago
June 19, 2026 at 07:56 PM UTC