---
id: CVE-2026-55778
title: >-
  parse-server: Stored XSS via non-standard file extension bypassing file upload
  extension blocklist
summary: >-
  parse-server: Stored XSS via non-standard file extension bypassing file upload
  extension blocklist
severity: low
cwe:
  - CWE-434
vendor: parse-server
product: parse-server
ecosystem: npm
affected:
  - 'parse-server >= 9.0.0, < 9.9.1-alpha.11'
  - parse-server <= 8.6.80
patched:
  - parse-server 9.9.1-alpha.11
  - parse-server 8.6.81
published: '2026-06-19'
updated: '2026-06-19'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-v8x7-r927-cc93'
references:
  - url: >-
      https://github.com/parse-community/parse-server/security/advisories/GHSA-v8x7-r927-cc93
  - url: 'https://github.com/parse-community/parse-server/pull/10505'
  - url: 'https://github.com/parse-community/parse-server/pull/10506'
  - url: 'https://github.com/advisories/GHSA-v8x7-r927-cc93'
tags:
  - ghsa
  - npm
ingestedAt: '2026-06-22T15:52:21.033Z'
epss: 0.00553
epssPercentile: 0.43791
---

## Overview

### Impact

Parse Server's default `fileUpload.fileExtensions` blocklist is intended to prevent uploading files that browsers render as active content (such as HTML and SVG), which can be used to perform stored cross-site scripting (XSS) attacks against other users. The blocklist could be bypassed by uploading a file whose extension is not an exact match of a blocked extension (for example a non-standard or compound extension) together with a dangerous content type. On storage adapters that persist and serve the uploaded content type (such as S3 and GCS), the file is then served with the attacker-supplied content type, enabling stored XSS against users who open the file URL.

This affects the default configuration, in which authenticated users are allowed to upload files. The default GridFS/filesystem adapter sets the `X-Content-Type-Options: nosniff` response header, which mitigates browser rendering on that adapter, but the upload restriction itself is still bypassed. This is an incomplete-fix follow-up of GHSA-vr5f-2r24-w5hc and GHSA-7wqv-xjf3-x35v.

### Patches

The file upload extension validation now also evaluates the request content type against the configured blocklist whenever the filename's extension is not a recognized type. As a result, a dangerous content type can no longer be preserved by uploading a file with a non-standard extension, and such uploads are rejected.

### Workarounds

Configure `fileUpload.fileExtensions` as a strict allowlist of only the file extensions your application needs (for example `["^(png|jpe?g|gif|pdf)$"]`) instead of relying on the default blocklist. Additionally, serve uploaded files from a separate domain than the application, so that any executed content is isolated from the application's origin.

## Affected packages

- `parse-server >= 9.0.0, < 9.9.1-alpha.11`
- `parse-server <= 8.6.80`

## Remediation

Upgrade to a patched release:

- `parse-server 9.9.1-alpha.11`
- `parse-server 8.6.81`
