Home

Description

Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI workflow is triggered in a way that grants the GitHub Actions workflow elevated permissions, giving it access to GitHub secrets and write permissions which are defined in the workflow. Code from a fork or lifecycle scripts is potentially included. Only the repository's CI/CD infrastructure is affected, including any public GitHub forks with GitHub Actions enabled. This issue is fixed version 8.6.0-alpha.2 and commits 6b9f896 and e3d27fe.

PUBLISHED Reserved 2025-12-10 | Published 2025-12-12 | Updated 2025-12-12 | Assigner GitHub_M




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-94: Improper Control of Generation of Code ('Code Injection')

CWE-269: Improper Privilege Management

Product status

< 8.6.0-alpha.2
affected

References

github.com/...server/security/advisories/GHSA-6w8g-mgvv-3fcj

github.com/...ommit/6b9f8963cc3debf59cd9c5dfc5422aff9404ce9d

github.com/...ommit/e3d27fea08c8d8bdd9770a689bc2d757cda48b66

cve.org (CVE-2025-67727)

nvd.nist.gov (CVE-2025-67727)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.