CVE-2026-27609: Parse Dashboard is Missing CSRF Protection for its Agent Endpoint
The AI Agent API endpoint (POST /apps/:appId/agent) lacks CSRF protection. An attacker can craft a malicious page that, when visited by an authenticated dashboard user, submits requests to the agent endpoint using the victim’s session.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-27609 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →