CVE-2026-33163 | parse-community parse-server up to 8.6.49/9.6.0-alpha.36 Personal Information toJSONwithObjects information disclosure (GHSA-5hmj-jcgp-6hff / EUVD-2026-12994)
A vulnerability described as problematic has been identified in parse-community parse-server up to 8.6.49/9.6.0-alpha.36. The impacted element is the function toJSONwithObjects of the component Personal Information Handler. Executing a manipulation can lead to information disclosure.
This vulnerability is tracked as CVE-2026-33163. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.