Detects Parse Server instances vulnerable to JWT audience validation bypass in the Google, Apple, and Facebook authentication adapters. When clientId (Google/Apple) or appIds (Facebook) is not configured, the adapter passes undefined as the audience to jwt.verify, which silently skips audience validation. Facebook Limited Login is vulnerable regardless of configuration because the adapter passed clientId — never present in the facebook options struct — instead of appIds. An unauthenticated attacker who possesses a validly signed Google/Apple/Facebook JWT issued for any app (including their own) can authenticate as any user on the target Parse Server by presenting that token as authData. Affects all versions before 8.6.10 and 9.0.0 through 9.5.0-alpha.10. Update to 8.6.10 or 9.5.0-alpha.11 or later.
Is your app exploitable through CVE-2026-30863?
Scan your domain free