Skip to main content

External Control of File Name or Path

CVE-2025-55746

Severity High
Score 7.5/10

Summary

Directus is a real-time API and App dashboard for managing SQL database content. In affected versions, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident metadata) and / or upload new files, with arbitrary content and extensions, which won't show up in the Directus UI. This issue affects directus versions 10.8.0 through 11.9.2 and @directus/api versions 14.1.0 through 28.0.2.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • NONE

CWE-73 - External Control of File Name or Path

The software allows user input to control or influence paths or file names that are used in filesystem operations.

References

Advisory Timeline

  • Published