Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
gha-lab-51c6b6d0a0 — Lab reproducing CVE-2025-67727 (parse-community/parse-server ci-performance.yml pull_request_target RCE at e78e58d) — authorized security research | Kitploit
Tools/GitHubGitHub/pvharmo2/gha-lab-51c6b6d0a0
Vulnerability AnalysisExploitationLearning & EducationCurated Resources
GitHubpvharmo2/gha-lab-51c6b6d0a0

gha-lab-51c6b6d0a0

Lab reproducing CVE-2025-67727 (parse-community/parse-server ci-performance.yml pull_request_target RCE at e78e58d) — authorized security research

View Repository
29 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Automated research artifact — not the upstream project.

This repository is a disposable lab built by an automated harness for a master's thesis at Université Laval on reproducing published GitHub Actions workflow vulnerabilities. It is a verbatim snapshot of parse-community/parse-server at commit e78e58d77858ea0ca6a7e9511c0df2fbc53cc567 (2025-12-04), redistributed under that project's own licence, whose file is included unchanged in this snapshot.

The upstream project is not involved, is never targeted, and the vulnerability studied here is already public. Every secret and variable in this repository is a randomly generated dummy value — no real credential is present. Action references and runner images are pinned to what they resolved to on 2025-12-04; see pinning.md in the harness output for every change made to the snapshot.

Questions or objections: [email protected]


parse-repository-header-server


Build Status Build Status Snyk Badge Coverage auto-release

Node Version MongoDB Version Postgres Version

npm latest version npm alpha version

[Backers on Open Collective][open-collective-link] [Sponsors on Open Collective][open-collective-link] Forum Twitter Chat


Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server works with the Express web application framework. It can be added to existing web applications, or run by itself.

The full documentation for Parse Server is available in the wiki. The Parse Server guide is a good place to get started. An API reference and Cloud Code guide are also available. If you're interested in developing for Parse Server, the Development guide will help you get set up.


A big thank you 🙏 to our sponsors and backers who support the development of Parse Platform!

Bronze Sponsors

Bronze Sponsors


  • Flavors & Branches
    • Long Term Support
  • Getting Started
    • Running Parse Server
      • Compatibility
        • Node.js
        • MongoDB
        • PostgreSQL
      • Locally
      • Docker Container
      • Saving and Querying Objects
      • Connect an SDK
    • Running Parse Server elsewhere
      • Sample Application
      • Parse Server + Express
    • Parse Server Health
      • Status Values
  • Configuration
    • Basic Options
    • Client Key Options
    • Access Scopes
    • Email Verification and Password Reset
    • Password and Account Policy
    • Custom Routes
      • Example
      • Reserved Paths
      • Parameters
    • Custom Pages
    • Using Environment Variables
    • Available Adapters
    • Configuring File Adapters
    • Idempotency Enforcement
    • Localization
      • Pages
        • Localization with Directory Structure
        • Localization with JSON Resource
        • Dynamic placeholders
        • Reserved Keys
        • Parameters
    • Logging
  • Deprecations
  • Live Query
  • GraphQL
    • Running
      • Using the CLI
      • Using Docker
      • Using Express.js
    • Checking the API health
    • Creating your first class
    • Using automatically generated operations
    • Customizing your GraphQL Schema
    • Learning more
  • Contributing
  • Contributors
  • Sponsors
  • Backers

Flavors & Branches

Parse Server is available in different flavors on different branches:

  • The main branches are [release][log_release] and [alpha][log_alpha]. See the changelog overview for details.
  • The long-term-support (LTS) branches are named release-<version>.x.x, for example release-5.x.x. LTS branches do not have pre-release branches.

Long Term Support

Long-Term-Support (LTS) is provided for the previous Parse Server major version. For example, Parse Server 5.x will receive security updates until Parse Server 6.x is superseded by Parse Server 7.x and becomes the new LTS version. While the current major version is published on branch release, a LTS version is published on branch release-#.x.x, for example release-5.x.x for the Parse Server 5.x LTS branch.

Download Tool