PT-2025-46914 · Directus · Directus

Published

2025-11-13

·

Updated

2026-04-05

·

CVE-2025-64748

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Directus versions prior to 11.13.0
Description Directus allows authenticated users to search concealed or sensitive fields when they have read permissions. While the actual values are masked, successful matches can be detected through returned records, enabling enumeration attacks on sensitive data. The vulnerability affects fields like token, tfa secret, and password within the directus users collection. Attackers can potentially verify valid authentication tokens, identify accounts using known compromised passwords, and confirm the existence of sensitive values. The default application access permissions can automatically expose deployments using recommended settings.
Recommendations Update to Directus version 11.13.0 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-64748
GHSA-8JPW-GPR4-8CMH

Affected Products

Directus