Skip to content

Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries

High severity GitHub Reviewed Published Mar 13, 2026 in parse-community/parse-server • Updated Mar 19, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts