npm package report

Is @directus/types safe?

1 known vulnerability, worst severity LOW.

cvss
3.5

how bad it is if exploited, out of 10

epss
0.40%

chance of exploitation in the next 30 days

xyz score
1.7

CyberXYZ composite, out of 10

fig. 01 — GHSA-56p6-qw3c-fq2g, the advisory selected below

// advisories

GHSA-56p6-qw3c-fq2g

LOWCVE-2025-30351

Since the user status is not checked when verifying a session token a suspended user can use the token generated in session auth mode to access the API despite their status.

Affected
>= 11.0.7, < 13.0.0
Fixed in
13.0.0
Weakness
CWE-672
Published
2025-03-26
Source
github

GHSANVDMITREreferencereference


// dependencies

6 direct, 1 carrying known advisories, worst MEDIUM

Sign in for dependency paths and remediation

// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 02:50 UTC. The most recent advisory here was published 2025-03-26. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @directus/types safe? npm package security report | CyberXYZ