Junglewise Threat Intelligence

CVE-2025-64746: Directus improper permission handling on deleted fields

CVE-2025-64746 · Severity: low · CVSS 3.1 · Published 2025-11-14

Technologies: directus (npm). Vendors: Directus, npm.

Executive brief

Directus is a headless CMS and API management platform that organizations use to manage content and data access controls. When fields are deleted from collections, the system fails to properly clean up associated field-level permissions. If an administrator later creates a new field with the same name, it automatically inherits the old permissions, potentially granting unintended access to sensitive data without explicit reconfiguration.

Technical details

The vulnerability is an authorization bypass caused by improper cleanup of field-level permissions in the Directus permissions table when fields are deleted. When a field is removed from a collection, its reference in the permissions table persists as stale data. If a new field is subsequently created with the same name, it automatically re-applies the old permission entry, bypassing the expected permission reset. An authenticated attacker with the ability to create fields in a collection can exploit this by creating a field that matches a previously deleted one, inheriting unintended read or write permissions. The vulnerability requires user interaction (field creation) and low-level privileges. A fix is available in version 11.13.0.

Affected products

  • Directus Directus < 11.13.0

Timeline

  • 2025-11-13: disclosed: Advisory published
  • 2025-11-13: patched: Fix available in version 11.13.0

References

Related threats