Information disclosure in Directus - CVE-2025-30352
Published: March 26, 2025 / Updated: April 23, 2026
Directus
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the search query parameter handling when processing search queries on collections. A remote attacker can send a search query for fields they are not permitted to view to disclose sensitive information.
Exploitation is possible when the attacker has access to a collection and can use the search query parameter against non-permitted string or numeric fields.