Unrated severityNVD Advisory· Published Aug 5, 2026· Updated Aug 5, 2026
Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation
CVE-2026-10716
Description
Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with geometry but contains attacker-controlled SQL syntax after the geometry subtype.This issue affects Directus: before 12.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- fluidattacks.com/es/advisories/metallicamitrethird-party-advisory
- github.com/directus/directus/security/advisories/GHSA-chfm-g7r3-vv42mitrevendor-advisory
News mentions
0No linked articles in our index yet.