VULNERABILITY OVERVIEW Directus versions prior to 11.16.1 contain an open redirect vulnerability in the login redirection logic. The isLoginRedirectAllowed function fails to properly validate malformed URLs, enabling attackers to bypass the redirect allow-list and redirect authenticated users to arbitrary external domains. This affects the widely-used real-time API and database management dashboard product. SEVERITY ASSESSMENT The vulnerability carries a CVSS 3.1 score of 6.1 (Medium), with a network-based attack vector requiring no privileges but necessitating user interaction. Attack complexity is low, making exploitation straightforward. The impact is limited to confidentiality and integrity concerns with no availability impact, as attackers can only redirect authenticated users to external sites rather than compromise system functionality or data directly. EXPLOITATION STATUS This vulnerability shows minimal active exploitation risk. It is not currently on the Known Exploited Vulnerabilities list, and the EPSS score of 0.00018 indicates extremely low probability of exploitation in the wild relative to other CVEs. No publicly disclosed exploit code is currently widespread, and community attention appears limited given the low threat indicators. Organizations should prioritize patching to version 11.16.1, but this is not an immediate critical threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.16.1CPE matchmatch criteria | cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.