PT-2025-29528 · Directus · Directus

Br41Nslug

·

Published

2025-07-14

·

Updated

2025-07-29

·

CVE-2025-53887

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Directus versions 9.0.0 through 11.8.99
Description: Directus is a real-time API and App dashboard for managing SQL database content. The exact Directus version number is exposed by the /server/specs/oas endpoint without authentication in versions prior to 11.9.0. This allows a malicious attacker to identify the specific running version and search for known vulnerabilities in Directus core or its dependencies.
Recommendations: Update to Directus version 11.9.0 or later.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-53887
GHSA-RMJH-CF9Q-PV7Q

Affected Products

Directus