---
id: CVE-2025-68115
title: >-
  Parse Server is an open source backend that can be deployed to any
  infrastructure that can run Node.js
summary: >-
  Parse Server is an open source backend that can be deployed to any
  infrastructure that can run Node.js. In versions prior to 8.6.1 and
  9.1.0-alpha.3, a Reflected Cross-Site Scripting (XSS) vulnerability exists in
  Parse Server's password …
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: parseplatform
product: parse-server
affected:
  - parse-server < 8.6.1
  - parse-server = 9.0.0
  - parse-server = 9.1.0
patched:
  - parse-server 8.6.1
published: '2025-12-16'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68115'
references:
  - url: 'https://github.com/parse-community/parse-server/pull/9985'
    label: security-advisories@github.com
  - url: 'https://github.com/parse-community/parse-server/pull/9986'
    label: security-advisories@github.com
  - url: >-
      https://github.com/parse-community/parse-server/security/advisories/GHSA-jhgf-2h8h-ggxv
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00219
epssPercentile: 0.11228
ingestedAt: '2026-10-07T20:46:46.946Z'
---

## Overview

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Parse Server's password reset and email verification HTML pages. The patch, available in versions 8.6.1 and 9.1.0-alpha.3, escapes user controlled values that are inserted into the HTML pages. No known workarounds are available.

## Affected

- `parse-server < 8.6.1`
- `parse-server = 9.0.0`
- `parse-server = 9.1.0`

## Remediation

Upgrade past the affected range:

- `parse-server 8.6.1`
