Information Disclosure Vulnerability in Directus API Dashboard by Directus
CVE-2025-53886
What is CVE-2025-53886?
Directus, a platform for managing SQL database content in real-time via APIs, has a vulnerability in its logging mechanism. Versions from 9.0.0 up to 11.8.0 log detailed information about incoming requests when using the WebHook trigger, which includes sensitive data such as access and refresh tokens stored in cookies. This poses a risk where malicious administrators with access to these logs could exploit the information to hijack user sessions within the token's validity period. The vulnerability has been addressed in version 11.9.0 of Directus.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
directus >= 9.0.0, < 11.9.0
References
CVSS V3.1
Timeline
Vulnerability published
