Remote Code Execution Vulnerability in Parse JavaScript SDK by Parse Community
CVE-2025-62374
What is CVE-2025-62374?
The Parse JavaScript SDK, which facilitates access to the powerful Parse Server from JavaScript applications, is vulnerable to remote code execution due to the injection of malicious payloads. This issue affects several functionalities, including the ParseObject methods and internal object state mutations, prior to version 7.0.0. Attackers could exploit this vulnerability to execute arbitrary code remotely. Users are advised to upgrade to version 7.0.0, where this vulnerability has been addressed, to ensure the security of their applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Parse-SDK-JS < 7.0.0-alpha.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
