MEDIUM 4.3 npm

Parse Server's Session Update endpoint allows overwriting server-generated session fields

GHSA-jc39-686j-wp6q · BIT-parse-2026-33527 · CVE-2026-33527

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

An authenticated user can overwrite server-generated session fields such as expiresAt and createdWith when updating their own session via the REST API. This allows bypassing the server's configured session lifetime policy, making a session effectively permanent.

Patches

The fix blocks authenticated users from setting expiresAt and createdWith fields when updating a session. Master key and maintenance key operations are not affected.

Workarounds

There is no known workaround other than upgrading.

Resources

Ready to move

Start Securing

Free, no credit card | First findings in minutes