Executive brief
Directus is a headless CMS and API management platform. The REST API's error messages reveal whether restricted collections exist, allowing unauthorized users to enumerate collections they cannot access. An authenticated attacker can use different error responses to determine which restricted data collections are present in the system.
Technical details
The vulnerability is an information leakage issue (CWE-203, CWE-209) in the Directus REST API /items/{collection} endpoint. The API returns distinct error messages for unauthorized access to an existing collection versus requests for a non-existent collection, creating an observable discrepancy. An authenticated user with low privileges can exploit this by comparing error messages to determine whether a collection exists, even if they lack permission to access it. The attack requires network access and low-privilege authentication but no user interaction. Patches are available in directus version 11.13.0 and @directus/api version 32.0.0.
Affected products
- Directus Directus before 11.13.0
- Directus @directus/api before 32.0.0
Timeline
- 2025-11-13: disclosed
- 2025-11-13: patched: directus 11.13.0 and @directus/api 32.0.0