#VU120252 Permissions, Privileges, and Access Controls in Parse Server - CVE-2025-67727
Published: December 23, 2025
Parse Server
Parse Community
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists within the repository's CI/CD infrastructure, including any public GitHub forks with GitHub Actions enabled. A GitHub CI workflow is triggered in a way that grants the GitHub Actions workflow elevated permissions, giving it access to GitHub secrets and write permissions defined in the workflow that could potentially include code from a fork or lifecycle scripts.