Stored Cross-Site Scripting in Directus API Management Tool
CVE-2025-64747
5.5MEDIUM
What is CVE-2025-64747?
Directus, a popular real-time API and application dashboard for SQL database management, is susceptible to a stored cross-site scripting (XSS) vulnerability in versions before 11.13.0. This flaw allows users with 'upload files' and 'edit item' permissions to inject harmful JavaScript into the Block Editor interface. By exploiting the combination of file uploads and iframe srcdoc attributes, attackers can bypass Content Security Policy (CSP) protections, leading to persistent XSS execution risks. Users are advised to upgrade to version 11.13.0 or higher to mitigate this vulnerability.
Affected Version(s)
directus < 11.13.0
