Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g4v2-qx3q-4p64 | Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields` |
Wed, 15 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Parseplatform
Parseplatform parse-server |
|
| CPEs | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.8.0:alpha1:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.8.0:alpha2:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.8.0:alpha3:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.8.0:alpha4:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.8.0:alpha5:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.8.0:alpha6:*:*:*:node.js:*:* |
|
| Vendors & Products |
Parseplatform
Parseplatform parse-server |
|
| Metrics |
cvssV3_1
|
Wed, 08 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Parse Community
Parse Community parse Server |
|
| Vendors & Products |
Parse Community
Parse Community parse Server |
Tue, 07 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.7 and 8.6.75, the GET /sessions/me endpoint returns _Session fields that the server operator explicitly configured as protected via the protectedFields server option. Any authenticated user can retrieve their own session's protected fields with a single request. The equivalent GET /sessions and GET /sessions/:objectId endpoints correctly strip protected fields. This vulnerability is fixed in 9.8.0-alpha.7 and 8.6.75. | |
| Title | Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields` | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T20:23:31.190Z
Reserved: 2026-04-06T22:06:40.515Z
Link: CVE-2026-39381
Updated: 2026-04-07T20:23:28.592Z
Status : Analyzed
Published: 2026-04-07T20:16:32.790
Modified: 2026-04-15T15:57:20.193
Link: CVE-2026-39381
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:46:02Z
Github GHSA