Parse Server GraphQL API allowed unauthenticated schema introspection starting in version 5.3.0 and in affected releases before 7.5.3 and 8.2.2. The issue exposed the GraphQL schema metadata without requiring either a valid session token or the Parse master key. While the vulnerability did not directly disclose application data, it allowed remote parties to enumerate types, fields, queries, mutations, and related schema structure through GraphQL introspection, increasing visibility into backend capabilities and internal object models.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
graphQLPublicIntrospection option is available after upgrading, its use should be limited to temporary compatibility scenarios only and disabled as soon as possible.Patch, then assume compromise.
graphQLPublicIntrospection configuration option for temporary compatibility. Organizations should update to a fixed release and ensure public introspection is not enabled unless absolutely necessary for short-term transition purposes.No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.