VYPR

npm package

parse

pkg:npm/parse

Vulnerabilities (2)

  • CVE-2025-62374MedOct 14, 2025
    affected < 7.0.0fixed 7.0.0

    Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, injection of malicious payload allows attacker to remotely execute arbitrary code. ParseObject.fromJSON, ParseObject.pin, ParseObject.registerSubclass, ObjectState

  • CVE-2025-57324Sep 24, 2025
    affected < 7.0.0-alpha.1fixed 7.0.0-alpha.1

    parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse version 5.3.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, caus