CVE-2025-64748: Directus's conceal fields are searchable if read permissions enabled

Published Nov 13, 2025
·
Updated

Summary

A vulnerability allows authenticated users to search concealed/sensitive fields when they have read permissions. While actual values remain masked (), successful matches can be detected through returned records, enabling enumeration attacks on sensitive data.

Details

The system permits search operations on concealed fields in the directususers collection, including token, tfasecret, password. Matching records are returned with masked values, but their presence confirms the searched value exists.

The "Recommended Defaults" for "App Access" grant users full read permissions to their role/user records, inadvertently enabling them to search for any user's tokens, TFA secrets, and password hashes. Attackers can leverage known password hashes from breach databases to identify accounts with compromised passwords.

Impact

This vulnerability enables: - Token enumeration - Verification of valid authentication tokens - Password hash matching - Identification of accounts using known compromised passwords - Information disclosure - Confirmation of sensitive value existence without viewing actual data - Increased attack surface - Default permissions automatically expose all deployments using recommended settings

The risk is particularly high for password fields, where attackers can cross-reference publicly available hash databases to identify vulnerable accounts.

Other sources

Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11.13.0 allows authenticated users to search concealed/sensitive fields when they have read permissions. While actual values remain masked (), successful matches can be detected through returned records, enabling enumeration attacks on sensitive data. Version 11.13.0 fixes the issue.

MITRE

Affected Software

4 affected componentsFixes available
Directus Directus<11.13.0
npm/@directus/api<32.0.0
32.0.0
npm/directus<11.13.0
11.13.0
Monospace Directus Node.js<11.13.0

Event History

Nov 13, 2025
CVE Published
via MITRE·09:29 PM
Data Sourced
via MITRE·09:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
RemedyAffected Software
Advisory Published
via GitHub·11:06 PM
Data Sourced
via GitHub·11:06 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-64748?

CVE-2025-64748 is considered a medium severity vulnerability affecting Directus versions prior to 11.13.0.

2

How do I fix CVE-2025-64748?

To fix CVE-2025-64748, upgrade Directus to version 11.13.0 or later.

3

Who is affected by CVE-2025-64748?

Authenticated users with read permissions in Directus versions prior to 11.13.0 are affected by CVE-2025-64748.

4

What type of data exposure is possible with CVE-2025-64748?

CVE-2025-64748 allows users to search for concealed fields in Directus, potentially revealing sensitive information.

5

What is the impact of CVE-2025-64748?

The impact of CVE-2025-64748 includes the risk of unauthorized data access to sensitive fields, even when values are masked.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203