GitHub Actions Elevated Permissions Vulnerability in Parse Server
CVE-2025-67727
What is CVE-2025-67727?
In Parse Server versions before 8.6.0-alpha.2, a security vulnerability exists that allows GitHub Actions workflows to acquire elevated permissions. This flaw affects the CI/CD infrastructure of the repository, potentially granting access to sensitive GitHub secrets and write permissions defined in the workflow. Such an issue can lead to the unintended execution of code from forks or lifecycle scripts. Public GitHub forks with GitHub Actions enabled are particularly at risk. The vulnerability has been addressed in version 8.6.0-alpha.2 and associated commits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
parse-server < 8.6.0-alpha.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
