PT-2025-5336 · Directus · Directus

·

CVE-2025-24353

·

Published

2025-01-23

·

Updated

2025-11-18

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Directus versions prior to 11.2.0
Description The issue allows a typical user to specify an arbitrary role when sharing an item, enabling them to use a higher-privileged role to view fields they should not be able to see. This affects instances that use the share feature and have a specific roles hierarchy and fields not visible to certain roles.
Recommendations For versions prior to 11.2.0, update to version 11.2.0 or later, which contains a patch to resolve the issue. As a temporary workaround, consider restricting the use of the share feature to admins only, or limit the fields that can be shared to those visible to the sharing user.

Exploit

Fix

DoS

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05409
CVE-2025-24353
GHSA-PMF4-V838-29HG

Affected Products

Directus