---
id: CVE-2025-67727
title: >-
  Parse Server is an open source backend that can be deployed to any
  infrastructure that runs Node.js
summary: >-
  Parse Server is an open source backend that can be deployed to any
  infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub
  CI workflow is triggered in a way that grants the GitHub Actions workflow
  elevated permissi…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
  - CWE-269
vendor: parseplatform
product: parse-server
affected:
  - parse-server <= 8.5.0
  - parse-server = 8.6.0
published: '2025-12-12'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67727'
references:
  - url: >-
      https://github.com/parse-community/parse-server/commit/6b9f8963cc3debf59cd9c5dfc5422aff9404ce9d
    label: security-advisories@github.com
  - url: >-
      https://github.com/parse-community/parse-server/commit/e3d27fea08c8d8bdd9770a689bc2d757cda48b66
    label: security-advisories@github.com
  - url: >-
      https://github.com/parse-community/parse-server/security/advisories/GHSA-6w8g-mgvv-3fcj
    label: security-advisories@github.com
tags:
  - nvd
  - exploit-available
epss: 0.00418
epssPercentile: 0.3395
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/pvharmo2/gha-lab-51c6b6d0a0'
  checkedAt: '2026-10-07T20:47:22.829Z'
exploitAvailable: true
ingestedAt: '2026-10-07T20:46:46.894Z'
---

## Overview

Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI workflow is triggered in a way that grants the GitHub Actions workflow elevated permissions, giving it access to GitHub secrets and write permissions which are defined in the workflow. Code from a fork or lifecycle scripts is potentially included. Only the repository's CI/CD infrastructure is affected, including any public GitHub forks with GitHub Actions enabled. This issue is fixed version 8.6.0-alpha.2 and commits 6b9f896 and e3d27fe.

## Affected

- `parse-server <= 8.5.0`
- `parse-server = 8.6.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
