Exposed Logging Vulnerability in Directus Real-Time API and App Dashboard
CVE-2025-53885
What is CVE-2025-53885?
Directus, a real-time API and app dashboard designed for managing SQL database content, has a logging vulnerability that can expose sensitive user data. The flaw exists in versions 9.0.0 to 11.8.9 when utilizing Directus Flows for CRUD events. Using the 'Log to Console' operation with template strings, malicious administrators may inadvertently log sensitive information from other users during their creation or update processes. The vulnerability has been addressed in version 11.9.0. As a preventive measure, developers are advised to refrain from logging sensitive data to the console in production environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
directus >= 9.0.0, < 11.9.0
References
CVSS V3.1
Timeline
Vulnerability published
