Authorization bypass through user-controlled key in Directus - #VU141292
Published: August 7, 2026
Vulnerability details
The vulnerability allows a remote user to overwrite another user\'s file and rewrite its metadata.
The vulnerability exists due to authorization bypass through user-controlled key in the TUS resumable upload endpoint when processing upload replacement metadata. A remote user can supply a victim file id in the Upload-Metadata header to overwrite another user\'s file and rewrite its metadata.
Only instances with `TUS_ENABLED=true` are vulnerable. The issue affects upload replacement through the `replace_id` metadata key, and no victim interaction is required.