CVE-2026-33539 | parse-community parse-server up to 8.6.58/9.6.0-alpha.52 PostgreSQL Database group sql injection (GHSA-p2w6-rmh7-w8q3 / EUVD-2026-14976)
A vulnerability identified as critical has been detected in parse-community parse-server up to 8.6.58/9.6.0-alpha.52. Affected by this issue is some unknown functionality of the component PostgreSQL Database. This manipulation of the argument group causes sql injection.
This vulnerability is tracked as CVE-2026-33539. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.