Parse Server GraphQL Introspection Bypass Vulnerability

Vulnerability

A vulnerability in Parse Server versions 9.3.1-alpha.3 prior to 9.5.0-alpha.10 allows unauthenticated users to bypass GraphQL introspection controls. When the 'graphQLPublicIntrospection' feature is disabled, '__type' queries nested within inline fragments can be exploited to perform type reconnaissance. This issue does not affect '__schema' introspection.

Impact

Exploitation of this vulnerability allows for unauthorized type reconnaissance via GraphQL introspection.

Remediation

Users can upgrade to Parse Server version 9.5.0-alpha.10, where this vulnerability has been patched. Alternatively, the GraphQL endpoint can be configured to require master key authentication at the network layer.

Added: Mar 7, 2026, 5:20 PM
Updated: Mar 7, 2026, 5:20 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
0.6
exploitability
8.3
remediation
7.9
relevance
3.6
threat
0.0
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.