Path traversal in Directus - #VU141295
Published: August 7, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive files from the host filesystem.
The vulnerability exists due to path traversal in the Mail Service template engine when resolving user-supplied email template names. A remote privileged user can supply a crafted relative template path to disclose sensitive files from the host filesystem.
Exploitation requires the ability to configure a Flow \"Send Email\" operation and relies on the presence of a file at a traversed path that the Liquid engine will load and render.