{"id":"CVE-2025-68115","aliases":["BIT-parse-2025-68115","GHSA-jhgf-2h8h-ggxv"],"url":"https://o3.security/vulnerability/CVE-2025-68115","summary":"Parse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template Variables","details":"Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Parse Server's password reset and email verification HTML pages. The patch, available in versions 8.6.1 and 9.1.0-alpha.3, escapes user controlled values that are inserted into the HTML pages. No known workarounds are available.","published":"2025-12-16T00:56:23.452Z","modified":"2026-08-12T03:51:34.519444602Z","cvss":null,"epss":{"score":0.00214,"percentile":0.11511,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"parse-server","fixedVersion":"8.6.1"},{"ecosystem":"npm","name":"parse-server","fixedVersion":"9.1.0-alpha.3"}],"fix":{"url":"https://github.com/parse-community/parse-server/pull/9985","label":"parse-community/parse-server#9985"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68115.json"},{"type":"ADVISORY","url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-jhgf-2h8h-ggxv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68115"},{"type":"FIX","url":"https://github.com/parse-community/parse-server/pull/9985"},{"type":"FIX","url":"https://github.com/parse-community/parse-server/pull/9986"},{"type":"PACKAGE","url":"https://github.com/parse-community/parse-server"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:34.519444602Z"}}