PT-2025-29527 · Directus · Directus

Licitdev

·

Published

2025-07-14

·

Updated

2025-07-29

·

CVE-2025-53886

CVSS v3.1

4.5

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Directus versions 9.0.0 through 11.8.9
Description: Directus is a real-time API and App dashboard for managing SQL database content. When using Directus Flows with the WebHook trigger, all incoming request details, including security-sensitive data like access and refresh tokens in cookies, are logged. Malicious administrators with access to the logs can hijack user sessions within the token expiration time after triggering the Flow.
Recommendations: Update to Directus version 11.9.0 or later.

Exploit

Fix

Information Disclosure

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2025-53886
GHSA-F24X-RM6G-3W5V

Affected Products

Directus