PT-2025-46915 · Directus · Directus

Published

2025-11-13

·

Updated

2025-12-08

·

CVE-2025-64749

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Directus versions prior to 11.13.0
Description Directus REST API exhibits differing error messages when accessing existing but unauthorized collections versus non-existent collections via the /items/{collection} API endpoint. This discrepancy leaks information about the existence of collections to unauthorized users. The collection variable in the API endpoint is a key component of this issue. Specifically, when a user attempts to access a collection they lack permission for, the error message indicates the collection exists, while a request for a non-existent collection yields a different error message.
Recommendations Versions prior to 11.13.0 should be updated to version 11.13.0 or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2025-64749
GHSA-CPH6-524F-3HGR

Affected Products

Directus