CVE-2026-33163 Details
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `Parse.Cloud.afterLiveQueryEvent` trigger is registered for a class, the LiveQuery server leaks protected fields and `authData` to all subscribers of that class. Fields configured as protected via Class-Level Permissions (`protectedFields`) are included in LiveQuery event payloads for all event types (create, update, delete, enter, leave). Any user with sufficient CLP permissions to subscribe to the affected class can receive protected field data of other users, including sensitive personal information and OAuth tokens from third-party authentication providers. The vulnerability was caused by a reference detachment bug. When an `afterEvent` trigger is registered, the LiveQuery server converts the event object to a `Parse.Object` for the trigger, then creates a new JSON copy via `toJSONwithObjects()`. The sensitive data filter was applied to the `Parse.Object` reference, but the unfiltered JSON copy was sent to clients. The fix in versions 9.6.0-alpha.35 and 8.6.50 ensures that the JSON copy is assigned back to the response object before filtering, so the filter operates on the actual data sent to clients. As a workaround, remove all `Parse.Cloud.afterLiveQueryEvent` trigger registrations. Without an `afterEvent` trigger, the reference detachment does not occur and protected fields are correctly filtered.
A vulnerability in Parse Server versions 9.0.0 prior to 9.6.0-alpha.35 and in versions prior to 8.6.50 allows for the leakage of protected fields and authentication data to all subscribers of a class when a 'Parse.Cloud.afterLiveQueryEvent' trigger is registered. This issue arises because the LiveQuery server improperly handles sensitive data, sending unfiltered JSON copies to clients. As a result, users with the appropriate Class-Level Permissions can access protected information from other users, including personal details and OAuth tokens from third-party services.
To address this vulnerability, users can upgrade to Parse Server versions 9.6.0-alpha.35 or 8.6.50, where the issue has been patched. Alternatively, as a temporary workaround, users can remove all 'Parse.Cloud.afterLiveQueryEvent' trigger registrations, which will prevent the leakage of protected fields.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/parse-community/parse-server/pull/10232 | [email protected] | Issue Tracking |
| https://github.com/parse-community/parse-server/pull/10233 | [email protected] | Issue Tracking |
| https://github.com/parse-community/parse-server/security/advisories/GHSA-5hmj-jcgp-6hff | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| parseplatform parse-server | < 8.6.50 >= 9.0.0, < 9.6.0 9.6.0 alpha1 9.6.0 alpha10 9.6.0 alpha11 9.6.0 alpha12 9.6.0 alpha13 9.6.0 alpha14 9.6.0 alpha15 9.6.0 alpha16 9.6.0 alpha17 9.6.0 alpha18 9.6.0 alpha19 9.6.0 alpha2 9.6.0 alpha20 9.6.0 alpha21 9.6.0 alpha22 9.6.0 alpha23 9.6.0 alpha24 9.6.0 alpha25 9.6.0 alpha26 9.6.0 alpha27 9.6.0 alpha28 9.6.0 alpha29 9.6.0 alpha3 9.6.0 alpha30 9.6.0 alpha31 9.6.0 alpha32 9.6.0 alpha33 9.6.0 alpha34 9.6.0 alpha4 9.6.0 alpha5 9.6.0 alpha6 9.6.0 alpha7 9.6.0 alpha8 9.6.0 alpha9 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 19, 2026 | Initial Analysis | [email protected] |
| Mar 18, 2026 | New CVE Received | [email protected] |