Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code.
References
Configurations
No configuration.
History
25 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-25 22:16
Updated : 2026-06-26 16:19
NVD link : CVE-2021-47986
Mitre link : CVE-2021-47986
CVE.ORG link : CVE-2021-47986
JSON object : View
Products Affected
No product.
CWE
CWE-494
Download of Code Without Integrity Check
