VYPR
Medium severity6.5NVD Advisory· Published Nov 13, 2025· Updated Jun 17, 2026

CVE-2025-64748

CVE-2025-64748

Description

Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11.13.0 allows authenticated users to search concealed/sensitive fields when they have read permissions. While actual values remain masked (****), successful matches can be detected through returned records, enabling enumeration attacks on sensitive data. Version 11.13.0 fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
directusnpm
< 11.13.011.13.0
@directus/apinpm
< 32.0.032.0.0

Affected products

4
  • cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:*+ 1 more
    • cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:*range: <11.13.0
    • (no CPE)range: < 11.13.0
  • ghsa-coords2 versions
    < 11.13.0+ 1 more
    • (no CPE)range: < 11.13.0
    • (no CPE)range: < 32.0.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.