VYPR
Medium severity6.3NVD Advisory· Published Jul 8, 2024· Updated Jun 17, 2026

CVE-2024-39701

CVE-2024-39701

Description

Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly handles _in, _nin operators. It evaluates empty arrays as valid so expressions like {"role": {"_in": $CURRENT_USER.some_field}} would evaluate to true allowing the request to pass. This results in Broken Access Control because the rule fails to do what it was intended to do: Pass rule if field matches any of the values. This vulnerability is fixed in 10.6.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
directusnpm
>= 9.23.0, < 10.6.010.6.0

Affected products

3
  • cpe:2.3:a:monospace:directus:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:monospace:directus:*:*:*:*:*:*:*:*range: >=9.23.0,<10.6.0
    • (no CPE)range: >= 9.23.0, < 10.6.0
  • ghsa-coords
    Range: >= 9.23.0, < 10.6.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.