API Exposure Vulnerability in Directus by Directus
CVE-2025-64748

6.5MEDIUM

Key Information:

Vendor

Directus

Status
Vendor
CVE Published:
13 November 2025

What is CVE-2025-64748?

A vulnerability in the Directus API allows authenticated users to search for concealed fields with read permissions. Although the actual values are masked, attackers can exploit this flaw to enumerate sensitive data through the results returned, posing a significant risk to data confidentiality. The issue has been resolved in version 11.13.0, which eliminates the potential for data exposure.

Affected Version(s)

directus < 11.13.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64748 : API Exposure Vulnerability in Directus by Directus