PT-2025-12983 · Directus · Directus

Published

2025-03-26

·

Updated

2025-08-26

·

CVE-2025-30352

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Directus versions 9.0.0-alpha.4 through 11.5.0
Description The issue allows users with access to a collection to filter items based on fields they do not have permission to view using the search query parameter. This enables the enumeration of unknown field contents because searchable columns are not checked against permissions when injecting the where clauses for applying the search query.
Recommendations For versions 9.0.0-alpha.4 through 11.5.0, update to version 11.5.0 to resolve the issue. As a temporary workaround, consider restricting access to the search query parameter until a patch is available.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-30352
GHSA-7WQ3-JR35-275C

Affected Products

Directus