{"id":"CVE-2025-62374","aliases":["GHSA-9f2h-7v79-mxw3"],"url":"https://o3.security/vulnerability/CVE-2025-62374","summary":"Parse Javascript SDK vulnerable to prototype pollution in `Parse.Object` and internal APIs","details":"### Summary\n\nPrototype pollution capabilities on various APIs.\n\n### Details\n\nInjection of malicious payload allows attacker to remotely execute arbitrary code. `Parse.Object` and internal APIs are affected, specifically:\n- `ParseObject.fromJSON`\n- `ParseObject.pin`\n- `ParseObject.registerSubclass`\n- `ObjectStateMutations` (internal)\n- `encode`/`decode` (internal)\n\n### PoC\n\nDemonstrative tests added as part of the fix.\n\n### References\n\n- https://github.com/parse-community/Parse-SDK-JS/security/advisories/GHSA-9f2h-7v79-mxw3\n- Patch https://github.com/parse-community/Parse-SDK-JS/releases/tag/7.0.0-alpha.1","published":"2025-10-14T20:06:43.697Z","modified":"2026-08-12T03:51:10.785565207Z","cvss":{"score":6.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"parse","fixedVersion":"7.0.0"}],"fix":{"url":"https://github.com/parse-community/Parse-SDK-JS/commit/00973987f361368659c0c4dbf669f3897520b132","label":"parse-community/Parse-SDK-JS@0097398"},"references":[{"type":"WEB","url":"https://github.com/parse-community/Parse-SDK-JS/releases/tag/7.0.0-alpha.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62374.json"},{"type":"ADVISORY","url":"https://github.com/parse-community/Parse-SDK-JS/security/advisories/GHSA-9f2h-7v79-mxw3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62374"},{"type":"FIX","url":"https://github.com/parse-community/Parse-SDK-JS/commit/00973987f361368659c0c4dbf669f3897520b132"},{"type":"FIX","url":"https://github.com/parse-community/Parse-SDK-JS/pull/2749"},{"type":"PACKAGE","url":"https://github.com/parse-community/Parse-SDK-JS"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:10.785565207Z"}}