CVE-2026-32248: Parse Logical Op Arraylike Bypass

Iteration over Parse logical operators ('$or', '$and', '$nor') guards recursion with only Array.isArray, which allows an attacker-supplied array-like plain object (e.g. {"0": {...}, "length": 1}) to bypass the check. Downstream query / matching / protected-field code may still iterate the value via numeric/length-based access. Add an explicit pre-check that

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0JS
greprules fetch cve-2026-32248-parse-logical-op-arraylike-bypass --engine opengrep

Description

Iteration over Parse logical operators ('$or', '$and', '$nor') guards recursion with only Array.isArray, which allows an attacker-supplied array-like plain object (e.g. {"0": {...}, "length": 1}) to bypass the check. Downstream query / matching / protected-field code may still iterate the value via numeric/length-based access. Add an explicit pre-check that