Information Disclosure Risk in Parse Server by Parse Community
CVE-2025-64502
What is CVE-2025-64502?
Parse Server, an open source backend for Node.js, has a critical vulnerability that allows any client to execute the MongoDB explain() method without requiring the master key. This exposure can reveal sensitive information about database schema structures, index usage, performance metrics, and potential attack vectors. Version 8.5.0-alpha.5 introduces a new databaseOptions.allowPublicExplain setting to restrict access to explain queries, which defaults to true to maintain compatibility with existing systems. Users are advised to implement middleware to block these queries from non-master-key requests or to monitor their usage for enhanced security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
parse-server < 8.5.0-alpha.5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
