Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 12 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Dec 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI workflow is triggered in a way that grants the GitHub Actions workflow elevated permissions, giving it access to GitHub secrets and write permissions which are defined in the workflow. Code from a fork or lifecycle scripts is potentially included. Only the repository's CI/CD infrastructure is affected, including any public GitHub forks with GitHub Actions enabled. This issue is fixed version 8.6.0-alpha.2 and commits 6b9f896 and e3d27fe. | |
| Title | Parse Server GitHub CI workflow vulnerable to RCE through Improper Privilege Management | |
| Weaknesses | CWE-269 CWE-94 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-12T20:37:07.495Z
Reserved: 2025-12-10T19:25:20.819Z
Link: CVE-2025-67727
Updated: 2025-12-12T20:37:02.520Z
Status : Awaiting Analysis
Published: 2025-12-12T07:15:45.087
Modified: 2025-12-12T15:17:31.973
Link: CVE-2025-67727
No data.
OpenCVE Enrichment
No data.