Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Directus version number is incorrectly being used as OpenAPI Spec version this means that it is being exposed by the `/server/specs/oas` endpoint without authentication. With the exact version information a malicious attacker can look for known vulnerabilities in Directus core or any of its shipped dependencies in that specific running version. Version 11.9.0 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Monospace
Monospace directus |
|
CPEs | cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:* | |
Vendors & Products |
Monospace
Monospace directus |
Tue, 15 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 15 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
Tue, 15 Jul 2025 00:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
Mon, 14 Jul 2025 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Directus version number is incorrectly being used as OpenAPI Spec version this means that it is being exposed by the `/server/specs/oas` endpoint without authentication. With the exact version information a malicious attacker can look for known vulnerabilities in Directus core or any of its shipped dependencies in that specific running version. Version 11.9.0 fixes the issue. | |
Title | Directus's exact version number is exposed by the OpenAPI Spec | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-14T23:40:59.198Z
Updated: 2025-07-15T19:49:03.448Z
Reserved: 2025-07-11T19:05:23.824Z
Link: CVE-2025-53887

Updated: 2025-07-15T13:24:43.102Z

Status : Analyzed
Published: 2025-07-15T00:15:23.847
Modified: 2025-07-16T14:19:39.037
Link: CVE-2025-53887

No data.