cvedb.io
CVE-2026-27609
MEDIUM · CVSS 6.5
EPSS exploitation probability: 0%
Published 2026-02-25T03:16:05.120 · Last modified 2026-06-26T17:00:03.350

Summary

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) lacks CSRF protection. An attacker can craft a malicious page that, when visited by an authenticated dashboard user, submits requests to the agent endpoint using the victim's session. The fix in version 9.0.0-alpha.8 adds CSRF middleware to the agent endpoint and embeds a CSRF token in the dashboard page. As a workaround, remove the `agent` configuration block from your dashboard configuration. Dashboards without an `agent` config are not affected.

Affected products

parseplatform — parse_dashboard

Does this affect you?

Add your gear to cvedb and we'll alert you only when parseplatform ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.