Aller au contenu

Fiche vulnérabilité

CVE-2025-55746 : faille élevée monospace directus (CVSS 7.5)

Description

Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident metadata) and / or upload new files, with arbitrary content and extensions, which won't show up in the Directus UI. This vulnerability is fixed in 11.9.3.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
20 août 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • monospace directus

Références

Rechercher une autre vulnérabilité dans la base CVE