Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25355 | Directus allows unauthenticated file upload and file modification due to lacking input sanitization |
Github GHSA |
GHSA-mv33-9f6j-pfmc | Directus allows unauthenticated file upload and file modification due to lacking input sanitization |
Tue, 13 Jan 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Monospace
Monospace directus |
|
| CPEs | cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Monospace
Monospace directus |
Thu, 21 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Directus
Directus directus |
|
| Vendors & Products |
Directus
Directus directus |
Wed, 20 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident metadata) and / or upload new files, with arbitrary content and extensions, which won't show up in the Directus UI. This vulnerability is fixed in 11.9.3. | |
| Title | Directus allows unauthenticated file upload and file modification due to lacking input sanitization | |
| Weaknesses | CWE-434 CWE-73 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-20T18:20:03.663Z
Reserved: 2025-08-14T22:31:17.685Z
Link: CVE-2025-55746
Updated: 2025-08-20T18:19:56.664Z
Status : Analyzed
Published: 2025-08-20T18:15:35.183
Modified: 2026-01-13T18:29:53.387
Link: CVE-2025-55746
No data.
OpenCVE Enrichment
Updated: 2025-08-21T12:30:51Z
EUVD
Github GHSA