Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p2w6-rmh7-w8q3 | Parse Server has SQL Injection through aggregate and distinct field names in PostgreSQL adapter |
Fri, 27 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Mar 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Parseplatform
Parseplatform parse-server |
|
| CPEs | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha10:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha11:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha12:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha13:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha14:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha15:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha16:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha17:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha18:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha19:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha1:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha20:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha21:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha22:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha23:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha24:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha25:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha26:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha27:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha28:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha29:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha2:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha30:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha31:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha32:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha33:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha34:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha35:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha36:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha37:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha38:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha39:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha3:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha40:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha41:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha42:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha43:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha44:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha45:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha46:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha47:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha48:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha49:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha4:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha50:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha51:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha52:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha5:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha6:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha7:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha8:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha9:*:*:*:node.js:*:* |
|
| Vendors & Products |
Parseplatform
Parseplatform parse-server |
|
| Metrics |
cvssV3_1
|
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Parse Community
Parse Community parse Server |
|
| Vendors & Products |
Parse Community
Parse Community parse Server |
Tue, 24 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.59 and 9.6.0-alpha.53, an attacker with master key access can execute arbitrary SQL statements on the PostgreSQL database by injecting SQL metacharacters into field name parameters of the aggregate $group pipeline stage or the distinct operation. This allows privilege escalation from Parse Server application-level administrator to PostgreSQL database-level access. Only Parse Server deployments using PostgreSQL are affected. MongoDB deployments are not affected. This issue has been patched in versions 8.6.59 and 9.6.0-alpha.53. | |
| Title | Parse Server: SQL injection via aggregate and distinct field names in PostgreSQL adapter | |
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-26T19:52:13.216Z
Reserved: 2026-03-20T18:05:11.831Z
Link: CVE-2026-33539
Updated: 2026-03-26T19:51:25.587Z
Status : Analyzed
Published: 2026-03-24T19:16:54.853
Modified: 2026-03-25T21:18:00.730
Link: CVE-2026-33539
No data.
OpenCVE Enrichment
Updated: 2026-03-26T12:18:55Z
Github GHSA