API Exposure Vulnerability in Directus by Directus
CVE-2025-64748
6.5MEDIUM
What is CVE-2025-64748?
A vulnerability in the Directus API allows authenticated users to search for concealed fields with read permissions. Although the actual values are masked, attackers can exploit this flaw to enumerate sensitive data through the results returned, posing a significant risk to data confidentiality. The issue has been resolved in version 11.13.0, which eliminates the potential for data exposure.
Affected Version(s)
directus < 11.13.0
