Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 26 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 25 Jun 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code. | |
| Title | Parse Server - Unreviewed Code Execution via Malicious Version Tags | |
| First Time appeared |
Parseplatform
Parseplatform parse-server |
|
| Weaknesses | CWE-494 | |
| CPEs | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Parseplatform
Parseplatform parse-server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-26T10:38:03.663Z
Reserved: 2026-06-21T02:08:33.231Z
Link: CVE-2021-47986
Updated: 2026-06-26T10:37:58.119Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T04:30:17Z