logo

CVE-2025-55746: Critical Directus Flaw Exposes Servers to Unauthenticated File Upload and RCE

ID: 3837195e-b54d-5999-882b-fbbd845e6407

STIX ID: report--3837195e-b54d-5999-882b-fbbd845e6407

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2025-08-22

Date Updated: 2026-04-22

Author: Ddos

...
...

**Directus CVE-2025-55746 (CVSS 9.3): critical unauthenticated file-write vulnerability allowing modification or upload of files (via the /files route and unsanitized filename_disk) that can enable phishing, file poisoning, or unauthenticated RCE in some deployments; patch to version 11.9.3 and review file-serving configurations immediately.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.