Launch Week Day 1: Announcing Security Design Review
UNKNOWN npm

parse-server's endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user

GHSA-79wj-8rqv-jvp5 · BIT-parse-2026-30229 · CVE-2026-30229

Published · Modified

Description

Impact

The readOnlyMasterKey can call POST /loginAs to obtain a valid session token for any user. This allows a read-only credential to impersonate arbitrary users with full read and write access to their data. Any Parse Server deployment that uses readOnlyMasterKey is affected.

Patches

The fix adds a check to the /logInAs handler.

Workarounds

There is no workaround other than not using readOnlyMasterKey.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes