Inclusion of Sensitive Information in Log Files in Directus - CVE-2025-53886
Published: May 5, 2026
Directus
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in the Flow logs feature when handling incoming WebHook trigger requests. A remote privileged user can access logged request details containing access and refresh tokens to disclose sensitive information.
User interaction is required for a user to trigger the Flow, and exploitation is limited to the token expiration time.