#VU124979 Improper access control in Parse Server - CVE-2025-53364
Published: April 6, 2026
Parse Server
Parse Community
Description
The vulnerability allows a remote attacker to disclose schema metadata.
The vulnerability exists due to improper access control in the GraphQL API introspection functionality when handling schema introspection queries. A remote attacker can send a schema introspection query to disclose schema metadata.
The issue exposes schema metadata but not actual data.