---
id: CVE-2025-62374
title: >-
  Parse Javascript SDK provides access to the powerful Parse Server backend from
  your JavaScript app
summary: >-
  Parse Javascript SDK provides access to the powerful Parse Server backend from
  your JavaScript app. Prior to 7.0.0, injection of malicious payload allows
  attacker to remotely execute arbitrary code.  ParseObject.fromJSON,
  ParseObject.pin…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L'
cwe:
  - CWE-1321
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62374'
references:
  - url: >-
      https://github.com/parse-community/Parse-SDK-JS/commit/00973987f361368659c0c4dbf669f3897520b132
    label: security-advisories@github.com
  - url: 'https://github.com/parse-community/Parse-SDK-JS/pull/2749'
    label: security-advisories@github.com
  - url: 'https://github.com/parse-community/Parse-SDK-JS/releases/tag/7.0.0-alpha.1'
    label: security-advisories@github.com
  - url: >-
      https://github.com/parse-community/Parse-SDK-JS/security/advisories/GHSA-9f2h-7v79-mxw3
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.0041
epssPercentile: 0.33147
ingestedAt: '2026-10-08T11:31:27.412Z'
---

## Overview

Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, injection of malicious payload allows attacker to remotely execute arbitrary code.  ParseObject.fromJSON, ParseObject.pin, ParseObject.registerSubclass, ObjectStateMutations (internal), and encode/decode (internal) are affected. This vulnerability is fixed in 7.0.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
