Critical severity9.8NVD Advisory· Published Dec 26, 2022· Updated Jun 17, 2026
CVE-2022-26969
CVE-2022-26969
Description
In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
directusnpm | < 9.7.0 | 9.7.0 |
Affected products
3Patches
Vulnerability mechanics
References
8- github.com/directus/directus/pull/12022nvdPatchThird Party AdvisoryWEB
- developer.mozilla.org/en-US/docs/Web/HTTP/CORSnvdTechnical DescriptionThird Party AdvisoryWEB
- github.com/advisories/GHSA-g27j-74fp-xfprghsaADVISORY
- github.com/directus/directus/blob/8daed9c41baeaf1d08c1e292bf9f0dcef65e48fb/docs/configuration/config-options.mdnvdThird Party AdvisoryWEB
- github.com/directus/directus/releases/tag/v9.7.0nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-26969ghsaADVISORY
- security.snyk.io/vuln/SNYK-JS-DIRECTUS-2441822nvdThird Party AdvisoryWEB
- github.com/directus/directus/security/advisories/GHSA-g27j-74fp-xfprghsaWEB
News mentions
0No linked articles in our index yet.