CVE-2025-62374 | Parse-SDK-JS up to 7.0.0 prototype pollution (GHSA-9f2h-7v79-mxw3)
A vulnerability classified as problematic has been found in Parse-SDK-JS up to 7.0.0. Affected by this vulnerability is the function ParseObject.fromJSON/ParseObject.pin/ParseObject.registerSubclass/ObjectStateMutations. This manipulation causes improperly controlled modification of object prototype attributes ('prototype pollution').
This vulnerability is tracked as CVE-2025-62374. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.