Missing Origin Validation in WebSockets in Directus - #VU141281
Published: August 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and perform unauthorized actions via an authenticated WebSocket session.
The vulnerability exists due to missing origin validation in WebSocket upgrade handler when processing cross-origin WebSocket upgrade requests that include a session cookie. A remote attacker can trick the victim into visiting an attacker-controlled page to disclose sensitive information and perform unauthorized actions via an authenticated WebSocket session.
User interaction is required, and exploitation is possible only when WebSockets are enabled and the victim\'s browser sends the session cookie with the cross-origin handshake.