Directus' exact version number is exposed by the OpenAPI Spec
Moderate severity
GitHub Reviewed
Published
Jul 14, 2025
in
directus/directus
•
Updated Jul 15, 2025
Description
Published by the National Vulnerability Database
Jul 15, 2025
Published to the GitHub Advisory Database
Jul 15, 2025
Reviewed
Jul 15, 2025
Last updated
Jul 15, 2025
Summary
The exact Directus version number is incorrectly being used as OpenAPI Spec version this means that it is being exposed by the
/server/specs/oas
endpoint without authentication.Impact
With the exact version information a malicious attacker can look for known vulnerabilities in Directus core or any of its shipped dependencies in that specific running version.
References