Input validation error in Directus - CVE-2025-64747
Published: April 23, 2026
Directus
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in the context of a user's session.
The vulnerability exists due to improper input validation in the Block Editor interface when processing JSON content containing HTML elements. A remote user can send a specially crafted PATCH request with malicious block editor content to execute arbitrary script in the context of a user's session.
User interaction is required to view the affected content, and exploitation requires the upload files and edit item permissions.