CVE-2026-30939 | parse-community parse-server up to 8.6.12/9.5.1-alpha.1 Cloud Function Endpoint prototype pollution (GHSA-5j86-7r7m-p8h6)
A vulnerability described as critical has been identified in parse-community parse-server up to 8.6.12/9.5.1-alpha.1. This issue affects some unknown processing of the component Cloud Function Endpoint. Executing a manipulation can lead to improperly controlled modification of object prototype attributes.
This vulnerability appears as CVE-2026-30939. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.