CVE-2026-22032: Directus has open redirect in SAML

Published Jan 6, 2026
·
Updated

Security Advisory: Open Redirect in Directus SAML Authentication

Summary

An open redirect vulnerability exists in the Directus SAML authentication callback endpoint. The RelayState parameter is used in redirects without proper validation against an allowlist of permitted domains.

Vulnerability Description

During SAML authentication, the RelayState parameter is intended to preserve the user's original destination. However, while the login initiation flow validates redirect targets against allowed domains, this validation is not applied to the callback endpoint. This allows an attacker to craft a malicious authentication request that redirects users to an arbitrary external URL upon completion.

The vulnerability is present in both the success and error handling paths of the callback.

Impact

- Phishing: Users can be redirected to attacker-controlled sites that mimic legitimate login pages - Credential theft: Chained attacks may leverage the redirect to capture OAuth tokens or authorization codes - Trust erosion: Users may lose confidence in the application's security posture

This vulnerability can be exploited without authentication.

Other sources

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.14.0, an open redirect vulnerability exists in the Directus SAML authentication callback endpoint. During SAML authentication, the RelayState parameter is intended to preserve the user's original destination. However, while the login initiation flow validates redirect targets against allowed domains, this validation is not applied to the callback endpoint. This allows an attacker to craft a malicious authentication request that redirects users to an arbitrary external URL upon completion. The vulnerability is present in both the success and error handling paths of the callback. This vulnerability can be exploited without authentication. Version 11.14.0 contains a patch.

MITRE

Affected Software

3 affected componentsFixes available
npm/@directus/api<32.1.1
32.1.1
npm/directus<11.14.0
11.14.0
Monospace Directus Node.js<11.14.0

Event History

Jan 6, 2026
Advisory Published
via GitHub·07:22 PM
Data Sourced
via GitHub·07:22 PM
DescriptionSeverityWeaknessAffected Software
Jan 8, 2026
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
RemedyAffected Software
Jul 14, 58060
Event
via FIRST·07:43 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-22032?

CVE-2026-22032 has been classified with a moderate severity level due to the potential for open redirect exploitation.

2

How do I fix CVE-2026-22032?

To mitigate CVE-2026-22032, upgrade to version 32.1.1 of @directus/api or version 11.14.0 of directus.

3

What does CVE-2026-22032 affect?

CVE-2026-22032 affects the SAML authentication callback endpoint in Directus, specifically relating to improper validation of the RelayState parameter.

4

What type of vulnerability is CVE-2026-22032?

CVE-2026-22032 is categorized as an open redirect vulnerability.

5

Can CVE-2026-22032 lead to further attacks?

Yes, CVE-2026-22032 may allow attackers to redirect users to malicious sites, potentially leading to phishing or other attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203