Operation on a Resource after Expiration or Release in Directus - CVE-2025-30351
Published: March 26, 2025 / Updated: April 23, 2026
Directus
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to operation on a resource after revocation in verifySessionJWT when verifying a session token for API access. A remote user can reuse a previously issued session token after the associated user has been suspended to disclose sensitive information.
The issue affects session auth mode, and exploitation requires obtaining a session token while the account is still active.