CVE-2025-68150
Parse Server is vulnerable to Server-Side Request Forgery (SSRF) via Instagram OAuth Adapter
EPSS 0.08%
Description
## Impact The Instagram authentication adapter allows clients to specify a custom API URL via the `apiURL` parameter in `authData`. This enables SSRF attacks and possibly authentication bypass if malicious endpoints return fake responses to validate unauthorized users. ## Patches Fixed by hardcoding the Instagram Graph API URL `https://graph.instagram.com` and ignoring client-provided `apiURL` values. ## Workarounds None.
How to fix CVE-2025-68150
To remediate CVE-2025-68150, upgrade the affected package to a fixed version below.
- —upgrade to 8.6.2 or later
- —upgrade to 9.1.1-alpha.1 or later
Is CVE-2025-68150 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 8.6.2, >= 9.0.0, < 9.1.1
- >= 9.0.0, < 9.1.1-alpha.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |