CVE-2025-53886: Directus doesn't redact tokens in Flow logs
Summary
When using Directus Flows with the WebHook trigger, all incoming request details are logged including security sensitive data like access and refresh tokens in cookies.
Impact
Malicious admins with access to the logs can hijack the user sessions within the token expiration time of them triggering the Flow.
Other sources
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows with the WebHook trigger all incoming request details are logged including security sensitive data like access and refresh tokens in cookies. Malicious admins with access to the logs can hijack the user sessions within the token expiration time of them triggering the Flow. Version 11.9.0 fixes the issue.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53886?
The severity of CVE-2025-53886 is considered to be high due to the leakage of sensitive data.
How do I fix CVE-2025-53886?
To fix CVE-2025-53886, upgrade to Directus version 11.9.0 or later.
What types of data are exposed in CVE-2025-53886?
CVE-2025-53886 exposes security-sensitive data, including access and refresh tokens.
What versions of Directus are affected by CVE-2025-53886?
Directus versions 9.0.0 through 11.9.0 are affected by CVE-2025-53886.
What is the impact of CVE-2025-53886 on users?
The impact of CVE-2025-53886 on users includes potential unauthorized access due to logged sensitive information.