CVE-2025-64430
Last modified
CVE-2025-64430 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2.0 through 7.5.3, and 8.0.0 through 8.3.1-alpha.1, there is a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality when trying to upload a Parse.File with uri parameter, allowing execution of an arbitrary URI. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2.0 through 7.5.3, and 8.0.0 through 8.3.1-alpha.1, there is a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality when trying to upload a Parse.File with uri parameter, allowing execution of an arbitrary URI. The vulnerability stems from a file upload feature in which Parse Server retrieves the file data from a URI that is provided in the request. A request to the provided URI is executed, but the response is not stored in Parse Server's file storage as the server crashes upon receiving the response. This issue is fixed in versions 7.5.4 and 8.4.0-alpha.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-64430?
How severe is CVE-2025-64430?
How do I fix CVE-2025-64430?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-64424Coolify is an open-source and self-hostable tool for managin…8.8
- CVE-2025-64425Coolify is an open-source and self-hostable tool for managin…8.1
- CVE-2025-64427ZimaOS is a fork of CasaOS, an operating system for Zima dev…6.5
- CVE-2025-64428Dataease is an open source data visualization analysis tool.…9.8
- CVE-2025-64429DuckDB is a SQL database management system. DuckDB implement…6.5
- CVE-2025-6443Mikrotik RouterOS VXLAN Source IP Improper Access Control Vu…7.2
- CVE-2025-64431Zitadel is an open source identity management platform. Vers…8.7
- CVE-2025-64432KubeVirt is a virtual machine management add-on for Kubernet…4.7
- CVE-2025-64433KubeVirt is a virtual machine management add-on for Kubernet…6.5
- CVE-2025-64434KubeVirt is a virtual machine management add-on for Kubernet…6.3
- CVE-2025-64435KubeVirt is a virtual machine management add-on for Kubernet…5.3
- CVE-2025-64436KubeVirt is a virtual machine management add-on for Kubernet…5.3
Are you affected by CVE-2025-64430?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
