#VU127110 Information disclosure in Directus - CVE-2024-54151
Published: December 9, 2024 / Updated: April 23, 2026
Directus
Directus
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in WebSocket GraphQL and REST operations when websocket authentication is configured as public. A remote attacker can send websocket subscription or CRUD requests to disclose sensitive information.
Only instances with WEBSOCKETS_GRAPHQL_AUTH or WEBSOCKETS_REST_AUTH set to public are vulnerable.