Open redirect in Directus - CVE-2026-35411
Published: April 23, 2026
Directus
Detailed vulnerability description
The vulnerability allows a remote attacker to redirect a victim to an attacker-controlled site.
The vulnerability exists due to url redirection to an untrusted site in the /admin/tfa-setup page when processing the redirect query parameter during 2fa setup. A remote attacker can send a crafted link to redirect a victim to an attacker-controlled site.
User interaction is required, and exploitation occurs after an administrator who has not yet configured two-factor authentication completes the setup process.