Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 26 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 25 Jun 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed only if it defined a git-based dependency referencing one of the affected tags (for example, parse-server#4.9.3). The code behind the tags was not reviewed or approved, and although no malicious code was identified, the introduction of security vulnerabilities could not be ruled out. | |
| Title | Parse Server - Arbitrary Code Execution via Malicious Version Tags | |
| First Time appeared |
Parseplatform
Parseplatform parse-server |
|
| Weaknesses | CWE-494 | |
| CPEs | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Parseplatform
Parseplatform parse-server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-26T18:42:21.725Z
Reserved: 2026-06-21T02:08:33.232Z
Link: CVE-2021-47987
Updated: 2026-06-26T18:14:36.303Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T05:45:04Z