Executive brief
Directus is a popular open-source headless CMS and data management platform. A flaw in its permission system allows users with multiple overlapping update policies to modify fields they should not have access to—including sensitive fields like user passwords. An authenticated attacker can exploit this to gain unauthorized modification access across different database items.
Technical details
The vulnerability exists in the permission validation logic introduced in Directus v11. When a user has two or more overlapping update policies that allow access to different fields on the same collection, the system incorrectly grants access to the union of all fields across all policies, rather than validating field-level permissions per item. For example, if policy A allows updating field_a on item id=1 and policy B allows updating field_b on item id=2, an authenticated user with both policies can update both fields on both items. The root cause is that the validateItemAccess function only verified access to the item as a whole, not individual fields. The fix evaluates field-level permissions for each requested update via a database query that returns access flags instead of actual values. Attack vector is network-based with low complexity and requires low privileges (an authenticated user account). Patch available: upgrade to directus v11.1.2 or @directus/api v23.1.0 or later.
Affected products
- Directus directus >=11.0.0, <11.1.2
- Directus @directus/api >=22.0.0, <23.1.0
Timeline
- 2025-02-19: disclosed: Advisory published
- 2025-02-19: patched: Patches released: directus v11.1.2 and @directus/api v23.1.0