PT-2026-30327 · Directus · Directus
Pov9En
·
Published
2026-04-04
·
Updated
2026-04-06
·
CVE-2026-35410
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Directus versions prior to 11.16.1
Description
Directus is a real-time API and App dashboard for managing SQL database content. An open redirect exists in the login redirection logic because the
isLoginRedirectAllowed function incorrectly identifies certain malformed URLs as internal, allowing attackers to bypass redirect allow-list validation and redirect users to arbitrary external domains after successful authentication. A parser differential exists between the server-side URL validation logic and how browsers interpret URL path segments containing backslashes, leading to misclassification of URLs. This can be exploited in SSO authentication flows to redirect users to attacker-controlled sites after authentication.Recommendations
Update to Directus version 11.16.1 or later.
Fix
Open Redirect
RCE
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Directus