Executive brief
Directus is a platform used to manage and visualize database content through APIs and dashboards. A security flaw allowed unauthorized users to view the underlying structure of the database—including table names, field names, and relationships—even when administrators had explicitly disabled this feature. While this does not directly expose the actual data records, it provides attackers with a blueprint of the system's architecture, which can be used to plan more sophisticated attacks.
Technical details
A vulnerability in Directus exists where the 'server_specs_graphql' resolver on the '/graphql/system' endpoint fails to respect the 'GRAPHQL_INTROSPECTION=false' configuration. While standard introspection queries like '__schema' and '__type' are correctly blocked, this specific endpoint returns an equivalent Schema Definition Language (SDL) representation of the entire schema. An unauthenticated attacker can access this endpoint over the network to discover collection names, field names, types, and relationships. This information disclosure bypasses intended security controls designed to hide the schema from public or unauthorized users. The issue is resolved in version 11.16.1.
Affected products
- Directus Directus < 11.16.1
Timeline
- 2026-04-02: advisory: Vendor advisory published on GitHub
- 2026-04-06: disclosed: CVE published to NVD
- 2026-04-06: patched: Fix released in version 11.16.1