CVE 6.5 MEDIUM

Directus exposes sensitive fields in revision history_CVE-2026-39943

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Description

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revision records (in directus_revisions) whenever items are created or updated. Due to the revision snapshot code not consistently calling the prepareDelta sanitization pipeline, sensitive fields (including user tokens, two-factor authentication secrets, external auth identifiers, auth data, stored credentials, and AI provider API keys) could be stored in plaintext within revision records. This vulnerability is fixed in 11.17.0.

Basic Information

ID CVE-2026-39943
Source GitHub_M
Published Apr 9, 2026 at 16:12
Modified Apr 10, 2026 at 14:06

Affected Product

Vendor directus
Product directus
Version < 11.17.0
Affected Versions directus directus < 11.17.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.