SB2026040750 - Cross-site scripting in Parse Server



SB2026040750 - Cross-site scripting in Parse Server

Published: April 7, 2026

Security Bulletin ID SB2026040750
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Cross-site scripting (CVE-ID: CVE-2026-32728)

The vulnerability allows a remote user to conduct stored cross-site scripting attacks and disclose sensitive information.

The vulnerability exists due to improper neutralization of input during web page generation in the file upload extension validation logic when processing uploaded files with a Content-Type header containing a MIME parameter or XML-based file extensions missing from the default blocklist. A remote user can upload a specially crafted file to conduct stored cross-site scripting attacks and disclose sensitive information.

User interaction is required for a victim to load the stored active content in a browser.


Remediation

Install update from vendor's website.