Description

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Directus version number is incorrectly being used as OpenAPI Spec version this means that it is being exposed by the `/server/specs/oas` endpoint without authentication. With the exact version information a malicious attacker can look for known vulnerabilities in Directus core or any of its shipped dependencies in that specific running version. Version 11.9.0 fixes the issue.

INFO

Published Date :

2025-07-14T23:40:59.198Z

Last Modified :

2025-07-15T19:49:03.448Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-53887 vulnerability.

Vendors Products
Directus
  • Directus
Monospace
  • Directus

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact