Information disclosure in Directus - CVE-2025-30353
Published: March 26, 2025 / Updated: April 23, 2026
Directus
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in webhook trigger flows when handling a failed condition operation with the "Data of Last Operation" response body. A remote attacker can trigger the flow with input that causes a ValidationError to disclose sensitive information.
Exposed data may include environment variables, API keys, authorization headers, user accountability information, and previous operational data.