CVE-2025-30353 Details
Description
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.5.0, when a Flow with the "Webhook" trigger and the "Data of Last Operation" response body encounters a ValidationError thrown by a failed condition operation, the API response includes sensitive data. This includes environmental variables, sensitive API keys, user accountability information, and operational data. This issue poses a significant security risk, as any unintended exposure of this data could lead to potential misuse. Version 11.5.0 fixes the issue.
A vulnerability in Directus versions 9.12.0 prior to 11.5.0 allows for the unintentional exposure of sensitive data through the API. This issue arises when a Flow with the 'Webhook' trigger and 'Data of Last Operation' response body encounters a ValidationError due to a failed condition operation. The API response in such cases includes environmental variables, sensitive API keys, user accountability information, and operational data, creating a significant security risk.
Users can upgrade to Directus version 11.5.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/directus/directus/security/advisories/GHSA-fm3h-p9wm-h74h | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/directus/directus/security/advisories/GHSA-fm3h-p9wm-h74h | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| monospace directus | >= 9.12.0, < 11.5.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 26, 2025 | Initial Analysis | [email protected] |
| Mar 26, 2025 | New CVE Received | [email protected] |
| Mar 26, 2025 | CVE Modified | CISA-ADP |