Asset Unavailability Vulnerability in Directus by Directus
CVE-2025-30225
5.3MEDIUM
What is CVE-2025-30225?
The Directus platform encounters an asset unavailability issue when handling a surge of malformed transformation requests. In particular, the vulnerability exists in the '@directus/storage-driver-s3' package versions starting from 9.22.0 and before 12.0.1, as well as in the Directus versions from 9.22.0 to prior to 11.5.0. During high-demand scenarios, all assets may return a 403 status, resulting in denied access across all policies, including Admin and Public access. This flaw necessitates upgrading to version 12.0.1 of the storage driver and version 11.5.0 of Directus to mitigate the risk.
Affected Version(s)
directus >= 9.22.0, < 11.5.0