CVE-2021-47986
parse-community parse-server
Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code.
- CVSS
- 7.7
- EPSS
- 0.12% 2.15% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.26