{"id":"CVE-2026-53724","title":"parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist","summary":"parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist","severity":"low","cwe":["CWE-79","CWE-434"],"vendor":"parse-server","product":"parse-server","affected":["parse-server >= 9.0.0, < 9.9.1-alpha.4","parse-server <= 8.6.78"],"patched":["parse-server 9.9.1-alpha.4","parse-server 8.6.79"],"published":"2026-06-19","updated":"2026-06-19","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-7wqv-xjf3-x35v","references":[{"url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-7wqv-xjf3-x35v"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53724"},{"url":"https://github.com/parse-community/parse-server/pull/10489"},{"url":"https://github.com/parse-community/parse-server/pull/10490"},{"url":"https://github.com/advisories/GHSA-7wqv-xjf3-x35v"}],"tags":["ghsa","npm"],"epss":0.00281,"epssPercentile":0.20865,"ingestedAt":"2026-06-22T15:52:21.060Z","ecosystem":"npm","slug":"CVE-2026-53724","body":"## Overview\n\n### Impact\n\nThe default file upload extension blocklist can be bypassed by appending a trailing dot to a filename whose extension would otherwise be blocked (e.g. `poc.svg.`). The trailing dot causes the extension parser to extract an empty string, which short-circuits the blocklist check, and the attacker-controlled Content-Type is forwarded to the storage adapter unchanged. Storage adapters that persist and serve the provided Content-Type (such as S3 or GCS) then serve the file with an active type such as `image/svg+xml`, enabling stored XSS when a victim opens the file URL. The default GridFS adapter is not affected because it sets `X-Content-Type-Options: nosniff` on responses.\n\n### Patches\n\nA filename ending in a dot is now treated as extensionless. When the parser produces an empty extension, the request handler falls back to validating the Content-Type subtype against the configured extension blocklist, matching the path that already catches truly extensionless uploads with a dangerous Content-Type. This is a follow-up to the previous fix [GHSA-vr5f-2r24-w5hc](https://github.com/parse-community/parse-server/security/advisories/GHSA-vr5f-2r24-w5hc).\n\n### Workarounds\n\nConfigure the storage adapter or CDN to derive Content-Type from the filename extension instead of using the stored Content-Type, or replace the default blocklist with an explicit allowlist of needed file extensions.\n\n## Affected packages\n\n- `parse-server >= 9.0.0, < 9.9.1-alpha.4`\n- `parse-server <= 8.6.78`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `parse-server 9.9.1-alpha.4`\n- `parse-server 8.6.79`","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}