SQL Injection Vulnerability in Directus PostgreSQL Implementation
CVE-2026-10716
7.5HIGH
What is CVE-2026-10716?
Directus is vulnerable to an authenticated SQL injection flaw during the collection creation process when utilizing PostgreSQL with PostGIS enabled. Administrators can inadvertently introduce risk by creating a geometry field where the type starts with 'geometry' but contains SQL syntax controlled by an attacker, enabling potential database access and manipulation. This issue impacts versions of Directus before 12.1.0, requiring prompt updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Directus Windows 0 < 12.1.0
