OsVault/npm/directus
npm

directus

35 known vulnerabilities · 0 critical · 7 high

CVE-2025-53889

Directus' insufficient permission checks can enable unauthenticated users to manually trigger Flows

Published Jul 15, 2025
CVE-2022-23080MEDIUM

Server-Side Request Forgery in Directus

Published Jun 23, 2022
CVE-2023-28443MEDIUM

directus vulnerable to Insertion of Sensitive Information into Log File

Published Mar 23, 2023
CVE-2024-27296MEDIUM

Directus version number disclosure

Published Mar 1, 2024
CVE-2026-35442HIGH
Risk: 47.05/100

Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries

Published Apr 4, 2026
GHSA-mvv8-v4jj-g47j

Directus: Sensitive fields exposed in revision history

Published Apr 4, 2026
CVE-2024-34708MEDIUM

Directus allows redacted data extraction on the API through "alias"

Published May 13, 2024
CVE-2020-19850MEDIUM

Directus API vulnerable to denial of service

Published Apr 4, 2023
CVE-2023-27474HIGH

directus vulnerable to HTML Injection in Password Reset email to custom Reset URL

Published Mar 7, 2023
CVE-2026-35410MEDIUM
Risk: 36.49/100

Directus: Open Redirect via Parser Bypass in OAuth2/SAML Authentication Flow

Published Apr 4, 2026
CVE-2025-30353

Directus's webhook trigger flows can leak sensitive data

Published Mar 26, 2025
CVE-2025-53885

Directus is vulnerable to sensitive data exposure as user data is not being redacted when logged

Published Jul 15, 2025
CVE-2022-24814HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in directus

Published Apr 5, 2022
CVE-2023-38503MEDIUM

Incorrect Permission Checking for GraphQL Subscriptions

Published Jul 25, 2023
CVE-2023-26492MEDIUM

Directus vulnerable to Server-Side Request Forgery On File Import

Published Mar 3, 2023
CVE-2022-36031MEDIUM

Directus vulnerable to unhandled exception on illegal filename_disk value

Published Aug 30, 2022
CVE-2025-30352

Directus `search` query parameter allows enumeration of non permitted fields

Published Mar 26, 2025
CVE-2026-22032

Directus has open redirect in SAML

Published Jan 6, 2026
GHSA-393c-p46r-7c95

Directus: Path Traversal and Broken Access Control in File Management API

Published Apr 4, 2026
CVE-2024-6534

Directus has an insecure object reference via PATH presets

Published Aug 27, 2024
CVE-2024-34709MEDIUM

Directus Lacks Session Tokens Invalidation

Published May 13, 2024
CVE-2023-27481MEDIUM

Directus vulnerable to extraction of password hashes through export querying

Published Mar 8, 2023
CVE-2025-53886

Directus tokens are not redacted in flow logs, exposing session credentials to all admin

Published Jul 15, 2025
CVE-2024-39896HIGH

Directus Allows Single Sign-On User Enumeration

Published Jul 8, 2024
CVE-2025-55746

Directus allows unauthenticated file upload and file modification due to lacking input sanitization

Published Aug 20, 2025
CVE-2023-45820MEDIUM

Directus crashes on invalid WebSocket message

Published Oct 19, 2023
CVE-2026-35411MEDIUM
Risk: 26.93/100

Directus: Open Redirect in Admin 2FA Setup Page

Published Apr 4, 2026
CVE-2026-35409HIGH
Risk: 49.29/100

Directus: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in File Import

Published Apr 4, 2026
CVE-2026-35441MEDIUM
Risk: 38.33/100

Directus: GraphQL Alias Amplification Denial of Service Due to Missing Query Cost/Complexity Limits

Published Apr 4, 2026
CVE-2026-26185

Directus Vulnerable to User Enumeration via Password Reset Timing Attack

Published Feb 12, 2026
CVE-2026-35413MEDIUM
Risk: 32.35/100

Directus: GraphQL Schema SDL Disclosure Setting

Published Apr 4, 2026
CVE-2025-53887

Directus' exact version number is exposed by the OpenAPI Spec

Published Jul 15, 2025
CVE-2026-35408HIGH
Risk: 55.7/100

Directus: Missing Cross-Origin Opener Policy

Published Apr 4, 2026
CVE-2026-35412HIGH
Risk: 41.18/100

Directus: TUS Upload Authorization Bypass Allows Arbitrary File Overwrite

Published Apr 4, 2026
GHSA-6q22-g298-grjh

Directus: Unauthenticated Denial of Service via GraphQL Alias Amplification of Expensive Health Check Resolver

Published Apr 4, 2026
Check your entire dependency tree at onceRun dependency scan →