CVE-2021-47986

Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code.

Scoring

Severity
HIGH
CVSS base score
7.7
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS probability
0.18%
CWE
CWE-494
Published
2026-06-25
Last modified
2026-06-26

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs