Incorrect authorization in Parse Server - #VU152593
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose GraphQL schema information.
The vulnerability exists due to incorrect authorization in the GraphQL introspection control when resolving an operation from the automatic persisted query cache. A remote attacker can replay a cached introspection query to disclose GraphQL schema information.
Only deployments with the GraphQL API mounted are affected. Exploitation requires an introspection operation to have previously been registered in the same server process by a client using the master key or maintenance key.