icon

We found results for “

CVE-2025-64749

Good to know:

icon
icon

Date: November 13, 2025

Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messaging was found in the Directus REST API in versions of Directus prior to version 11.13.0. The "/items/{collection}" API returns different error messages for two cases: when a user tries to access an existing collection which they are not authorized to access, and when user tries to access a non-existing collection. The two differing error messages leak the existence of collections to users which are not authorized to access these collections. Version 11.13.0 fixes the issue.

Severity Score

Severity Score

Weakness Type (CWE)

Observable Discrepancy

CWE-203

Generation of Error Message Containing Sensitive Information

CWE-209

Top Fix

icon

Upgrade Version

Upgrade to version directus - 11.13.0;@directus/api - 32.0.0;https://github.com/directus/directus.git - v11.13.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us