Detects Parse Server instances where the Cloud Function trigger store can be traversed via the JavaScript prototype chain. An attacker appends '.prototype.constructor' to a Cloud Function name in the API URL, causing the handler to resolve through the prototype chain while the validator store finds no validator — skipping requireUser, requireMaster, and custom validators entirely. Any Cloud Function defined with the 'function' keyword (not arrow functions) is exploitable. Update to Parse Server 8.6.67 or 9.7.0 or later.
Is your app exploitable through CVE-2026-34532?
Scan your domain free