GHSA-cph6-524f-3hgr · Severity: medium · Ecosystem: npm — Directus Vulnerable to Information Leakage in Existing Collections
Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messaging was found in the Directus REST API in versions of Directus prior to version 11.13.0. The `/items/{collection}` API returns different error messages for two cases: when a user tries to access an existing collection which they are not authorized to access, and when user tries to access a non-existing collection. The two differing error messages leak the existence of collections to users which are not authorized to access these collections. Version 11.13.0 fixes the issue.
Conclusion & alert: CVE-2025-64749 is rated Exploit Available (50/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.04%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-11 | 0.05% | 0.04% | -0.01% |
| 2 | 2026-03-15 | 0.03% | 0.05% | +0.02% |
| 3 | 2025-11-14 | — | 0.03% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.3 | 3.1 | MEDIUM |
|
2.8 | 1.4 | [email protected] |
GHSA-cph6-524f-3hgr · Severity: medium · Ecosystem: npm — Directus Vulnerable to Information Leakage in Existing Collections
| URL | Tags |
|---|---|
| https://github.com/directus/directus/commit/f99c9b89071f9d136cc9b0d0c182f2d24542bc31 | Patch |
| https://github.com/directus/directus/security/advisories/GHSA-cph6-524f-3hgr | Exploit Vendor Advisory |