CVE-2025-55746: Critical Directus Flaw Exposes Servers to Unauthenticated File Upload and RCE
ID: 3837195e-b54d-5999-882b-fbbd845e6407
STIX ID: report--3837195e-b54d-5999-882b-fbbd845e6407
Feed Name: securityonline.info
Threat Score
**Directus CVE-2025-55746 (CVSS 9.3): critical unauthenticated file-write vulnerability allowing modification or upload of files (via the /files route and unsanitized filename_disk) that can enable phishing, file poisoning, or unauthenticated RCE in some deployments; patch to version 11.9.3 and review file-serving configurations immediately.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
