PT-2026-30330 · Directus · Directus

Bugbunny-Research

+1

·

Published

2026-04-04

·

Updated

2026-04-06

·

CVE-2026-35413

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Directus (affected versions not specified)
Description When GRAPHQL INTROSPECTION=false is configured, Directus blocks standard GraphQL introspection queries but the /graphql/system endpoint's server specs graphql resolver returns an equivalent SDL representation of the schema. This bypasses introspection controls, exposing schema structure (collection names, field names, types, and relationships) to unauthenticated users at the public permission level, and to authenticated users at their permitted permission level. Administrators setting GRAPHQL INTROSPECTION=false had a false sense of security, as schema information remained accessible via the SDL endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-35413
GHSA-WXWM-3FXV-MRVX

Affected Products

Directus