GHSA-mv33-9f6j-pfmc
CRITICALCVE-2025-55746A vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident metadata) and / or upload new files, with arbitrary content and extensions, which won't show up in the Directus UI.
- Affected
- >= 14.1.0, < 28.0.2
- Fixed in
- 28.0.2
- Weakness
- CWE-73
- Published
- 2025-08-20
- Source
- github