Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-53886


Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows with the WebHook trigger all incoming request details are logged including security sensitive data like access and refresh tokens in cookies. Malicious admins with access to the logs can hijack the user sessions within the token expiration time of them triggering the Flow. Version 11.9.0 fixes the issue.


Published

2025-07-15T00:15:23.690

Last Modified

2025-07-16T14:19:03.560

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-200
    CWE-212
    CWE-532

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application monospace directus < 11.9.0 Yes

References