PT-2025-29526 · Directus · Directus

Br41N

·

Published

2025-07-14

·

Updated

2025-07-29

·

CVE-2025-53885

CVSS v3.1

4.2

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Directus versions 9.0.0 through 11.8.9
Description: Directus is a real-time API and App dashboard for managing SQL database content. When using Directus Flows to handle CRUD events for users, the "Log to Console" operation with a template string can be exploited by malicious administrators to log sensitive data from other users during creation or update processes.
Recommendations: Update to Directus version 11.9.0 or later. Avoid logging sensitive data to the console outside of development environments.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2025-53885
GHSA-X3VM-88HF-GPXP

Affected Products

Directus