CVE-2025-53364
Last modified
CVE-2025-53364 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.0 and before 7.5.3 and 8.2.2, the Parse Server GraphQL API previously allowed public access to the GraphQL schema without requiring a session token or the master key. EPSS estimates a 0.81% chance of exploitation in the next 30 days.
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.0 and before 7.5.3 and 8.2.2, the Parse Server GraphQL API previously allowed public access to the GraphQL schema without requiring a session token or the master key. While schema introspection reveals only metadata and not actual data, this metadata can still expand the potential attack surface. This vulnerability is fixed in 7.5.3 and 8.2.2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-53364?
How severe is CVE-2025-53364?
How do I fix CVE-2025-53364?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-53357GLPI, which stands for Gestionnaire Libre de Parc Informatiq…5.4
- CVE-2025-53358kotaemon is an open-source RAG-based tool for document compr…6.5
- CVE-2025-53359ethereum is a common ethereum structs for Rust. Prior to eth…6.9
- CVE-2025-5336The Click to Chat plugin for WordPress is vulnerable to Stor…6.4
- CVE-2025-53360pluginsGLPI's Database Inventory Plugin "manages" the Teclib…4.3
- CVE-2025-53363dpanel is an open source server management panel written in …4.8
- CVE-2025-53365The MCP Python SDK, called `mcp` on PyPI, is a Python implem…8.7
- CVE-2025-53366The MCP Python SDK, called `mcp` on PyPI, is a Python implem…8.7
- CVE-2025-53367DjVuLibre is a GPL implementation of DjVu, a web-centric for…8.4
- CVE-2025-53368Citizen is a MediaWiki skin that makes extensions part of th…5.4
- CVE-2025-53369Short Description is a MediaWiki extension that provides loc…8.6
- CVE-2025-5337The Slider, Gallery, and Carousel by MetaSlider plugin for W…5.4
Are you affected by CVE-2025-53364?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
