PT-2025-29527 · Directus · Directus
Licitdev
·
Published
2025-07-14
·
Updated
2025-07-29
·
CVE-2025-53886
CVSS v3.1
4.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Directus versions 9.0.0 through 11.8.9
Description:
Directus is a real-time API and App dashboard for managing SQL database content. When using Directus Flows with the WebHook trigger, all incoming request details, including security-sensitive data like access and refresh tokens in cookies, are logged. Malicious administrators with access to the logs can hijack user sessions within the token expiration time after triggering the Flow.
Recommendations:
Update to Directus version 11.9.0 or later.
Exploit
Fix
Information Disclosure
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Directus