CVE-2025-30353 is a sensitive data exposure vulnerability affecting Directus versions 9.12.0 through 11.4.x. When a Flow with a Webhook trigger and "Data of Last Operation" response body encounters a ValidationError, the API response inadvertently exposes sensitive information like environmental variables, API keys, and user data. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a high potential for impact due to unauthenticated network access and complete confidentiality compromise. There is currently no public exploit intelligence, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.12.0, < 11.5.0CPE matchmatch criteria | cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.