CVE-2026-31871 | parse-community parse-server up to 8.6.30/9.0.0 9.6.0-alpha.4 Parse Server REST API sql injection (GHSA-gqpp-xgvh-9h7h)
A vulnerability identified as critical has been detected in parse-community parse-server up to 8.6.30/9.0.0 9.6.0-alpha.4. This vulnerability affects unknown code of the component Parse Server REST API. This manipulation causes sql injection.
This vulnerability is registered as CVE-2026-31871. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.