Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI workflow is triggered in a way that grants the GitHub Actions workflow elevated permissions, giving it access to GitHub secrets and write permissions which are defined in the workflow. Code from a fork or lifecycle scripts is potentially included. Only the repository's CI/CD infrastructure is affected, including any public GitHub forks with GitHub Actions enabled. This issue is fixed version 8.6.0-alpha.2 and commits 6b9f896 and e3d27fe.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is an automated research snapshot of Parse Server rather than a conventional standalone exploit repository. Its security-relevant proof of concept is .github/workflows/ci-performance.yml. That workflow is triggered by pull_request_target, initially checks out the pull-request head, copies PR-controlled benchmark content, and later installs, builds, and executes PR code. This is unsafe because pull_request_target workflows execute in the base repository context rather than the untrusted fork context. The workflow explicitly has pull-request and issue write permissions, so arbitrary code supplied by a contributor PR can run with a privileged Actions token/context. No hard-coded reverse shell, exfiltration endpoint, CVE identifier, or destructive payload was found; exploitation requires an attacker-created PR carrying the payload. The 100-file snapshot primarily contains the Parse Server Node.js project scaffolding: npm package/build configuration, CLI wrappers, Docker build configuration, public password-reset and email-verification pages, CI/release workflows, benchmarking utilities, and unit tests. JavaScript is the primary language, with shell scripts, YAML workflows, HTML templates, and JSON configuration. The Parse Server application source tree is referenced by build scripts but is not represented in the supplied listing; the included benchmark and CI files are sufficient to identify the workflow vulnerability. The benchmark itself launches a local Parse endpoint on port 1337 and uses a local MongoDB instance, which are test-only resources rather than attacker command-and-control destinations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.