CVE-2025-24353

MEDIUM

Monospace Directus < 11.2.0 - Improper Privilege Management

Title source: rule
STIX 2.1

Description

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.2.0, when sharing an item, a typical user can specify an arbitrary role. It allows the user to use a higher-privileged role to see fields that otherwise the user should not be able to see. Instances that are impacted are those that use the share feature and have specific roles hierarchy and fields that are not visible for certain roles. Version 11.2.0 contains a patch the issue.

Scores

CVSS v3 5.0
EPSS 0.0035
EPSS Percentile 57.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-269
Status published
Products (3)
directus/app 0 - 13.3.1npm
monospace/directus < 11.2.0
npm/directus 0 - 11.2.0npm
Published Jan 23, 2025
Tracked Since Feb 18, 2026