External Control of File Name or Path
CVE-2025-55746
Summary
Directus is a real-time API and App dashboard for managing SQL database content. In affected versions, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident metadata) and / or upload new files, with arbitrary content and extensions, which won't show up in the Directus UI. This issue affects directus versions 10.8.0 through 11.9.2 and @directus/api versions 14.1.0 through 28.0.2.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- NONE
- NONE
CWE-73 - External Control of File Name or Path
The software allows user input to control or influence paths or file names that are used in filesystem operations.
References
Advisory Timeline
- Published