Impact
Parse Server 8.2.2 up to 8.6.91 and 9.0.0 up to 9.10.1-alpha.11 expose hidden class names through GraphQL error messages when public introspection is disabled. Crafted queries that trigger unknown‑argument or invalid enum value responses reveal internal pointer and relation target classes, allowing an attacker to map the application’s schema. This vulnerability is a classic example of CWE‑209, exposing sensitive implementation details without requiring authentication beyond knowledge of the public application ID.
Affected Systems
The affected product is Parse Server from Parse Community. Versions 8.2.2 through 8.6.91 and 9.0.0 through 9.10.1-alpha.11 are vulnerable. All installations that have public GraphQL access with introspection disabled are at risk.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, and the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. Attackers with only the public application ID can send custom GraphQL operations to trigger error responses that leak class names, so the attack vector is unauthenticated, network‑based exploitation. This information disclosure could facilitate future attacks by revealing the underlying data model.
OpenCVE Enrichment