CVE-2026-32248: Parse Logical Op Arraylike Bypasscve-2026-32248-parse-logical-op-arraylike-bypass
Iteration over Parse logical operators ('$or', '$and', '$nor') guards recursion with only Array.isArray, which allows an attacker-supplied array-like plain object (e.g. {"0": {...}, "length": 1}) to bypass the check. Downstream query / matching / protected-field code may still iterate the value via numeric/length-based access. Add an explicit pre-check that