vulns.co
/
GKData.io MCP

Parse Community · 2 min read

Parse Server: preserve safe file interpretation across storage and browsers

GHSA-r899-h629-j84r describes inconsistent interpretation of uploaded-file metadata across admission, storage and browser consumption. The maintainer reports stored cross-site scripting when unsupported filename types retained invalid media-type metadata. The affected storage configurations preserved that metadata; default GridFS is explicitly unaffected.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

The maintainer recommends corrected versions, application-specific file allowlists, origin separation for uploads and storage-layer anti-sniffing policy. Editorial lesson: admission checks and delivery behavior form one security contract. A successful upload validation result alone does not establish that later consumers will treat the object as inert data.

Before reading

  • Basic web upload handling and server-side validation
  • Content-type interpretation and processing lifecycle concepts

Context and limits

  • Requires upload permission, a storage/delivery configuration retaining supplied metadata, and another user opening the uploaded object. Browser-side script execution is maintainer-reported; production exploitation, account takeover and server compromise are not established.
  • The advisory lists affected ranges as <= 8.6.83 and >= 9.0.0, < 9.10.0-alpha.2. It identifies 8.6.84 and 9.10.0-alpha.2 as patched.
  • The version-8 and version-9 remediation records show June 25, 2026 merges and releases; the version-9 stable release 9.10.0 is dated July 13, 2026. These are software events, not educational-resource editions.
  • The advisory header identifies mtrezza as the publisher, and Credits lists CyberKareem as Finder and mtrezza as Coordinator. The reviewed advisory provides no explicit article-author byline, so the author field is left empty. No CVE is listed on the reviewed advisory.
  • The version-9 correction validates supplied media types for unrecognized filename extensions when extension filtering is enabled; disabling that filtering also disables this validation. Well-formed custom types remain subject to configured restrictions. This does not establish that all accepted content is harmless.
  • Learning prerequisites and the generalized consumer-contract lesson are editorial. No award claim is made.

Sources and provenance

  1. Stored XSS via malformed Content-Type bypassing file upload extension blocklist Parse Community · reviewed 2026-10-03
  2. Parse Server 9 remediation, pull request 10521 Parse Community · reviewed 2026-10-03
  3. Parse Server 8 remediation, pull request 10523 Parse Community · reviewed 2026-10-03
  4. Parse Server 9.10.0 release Parse Community · reviewed 2026-10-03
  5. Version-9 merged metadata-validation patch and configuration scope Parse Community · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software