CVE-2024-27298

CRITICAL10.0EPSS 0.31%

Parse Server literalizeRegexPart SQL Injection

Published: 3/1/2024Modified: 3/13/2026

Description

parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database. The vulnerability has been fixed in 6.5.0 and 7.0.0.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL10.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

References (7)