CVE-2025-24353
Last modified
CVE-2025-24353 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.2.0, when sharing an item, a typical user can specify an arbitrary role. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.2.0, when sharing an item, a typical user can specify an arbitrary role. It allows the user to use a higher-privileged role to see fields that otherwise the user should not be able to see. Instances that are impacted are those that use the share feature and have specific roles hierarchy and fields that are not visible for certain roles. Version 11.2.0 contains a patch the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Monospace | Directus | < 11.2.0 |
References
- https://github.com/directus/directus/pull/23716Issue Tracking
- https://github.com/directus/directus/security/advisories/GHSA-pmf4-v838-29hgExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-24353?
How severe is CVE-2025-24353?
How do I fix CVE-2025-24353?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-24346A vulnerability in the “Proxy” functionality of the web appl…7.5
- CVE-2025-24347A vulnerability in the “Network Interfaces” functionality of…6.5
- CVE-2025-24348A vulnerability in the “Network Interfaces” functionality of…5.4
- CVE-2025-24349A vulnerability in the “Network Interfaces” functionality of…7.1
- CVE-2025-24350A vulnerability in the “Certificates and Keys” functionality…7.1
- CVE-2025-24351A vulnerability in the “Remote Logging” functionality of the…8.8
- CVE-2025-24354imgproxy is server for resizing, processing, and converting …5.3
- CVE-2025-24355Updatecli is a tool used to apply file update strategies. Pr…7.1
- CVE-2025-24356fastd is a VPN daemon which tunnels IP packets and Ethernet …7.5
- CVE-2025-24357vLLM is a library for LLM inference and serving. vllm/model_…8.8
- CVE-2025-24358gorilla/csrf provides Cross Site Request Forgery (CSRF) prev…5.4
- CVE-2025-24359ASTEVAL is an evaluator of Python expressions and statements…8.4
Are you affected by CVE-2025-24353?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
