CVE-2026-33627: Parse Server exposes auth data via /users/me endpoint
(updated )
An authenticated user calling GET /users/me receives unsanitized auth data, including sensitive credentials such as MFA TOTP secrets and recovery codes. The endpoint internally uses master-level authentication for the session query, and the master context leaks through to the user data, bypassing auth adapter sanitization. An attacker who obtains a user’s session token can extract MFA secrets to generate valid TOTP codes indefinitely.
References
- github.com/advisories/GHSA-37mj-c2wf-cx96
- github.com/parse-community/parse-server
- github.com/parse-community/parse-server/commit/5b8998e6866bcf75be7b5bb625e27d23bfaf912c
- github.com/parse-community/parse-server/commit/875cf10ac979bd60f70e7a0c534e2bc194d6982f
- github.com/parse-community/parse-server/pull/10278
- github.com/parse-community/parse-server/pull/10279
- github.com/parse-community/parse-server/security/advisories/GHSA-37mj-c2wf-cx96
- nvd.nist.gov/vuln/detail/CVE-2026-33627
Code Behaviors & Features
Detect and mitigate CVE-2026-33627 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →