CVE-2025-64749 Overview
CVE-2025-64749 is an information disclosure vulnerability in Directus, an open-source real-time API and application dashboard for managing SQL database content. The flaw resides in the /items/{collection} REST API endpoint, which returns distinguishable error messages depending on whether a requested collection exists but is inaccessible or does not exist at all. Authenticated users with limited privileges can enumerate collection names they are not authorized to access by observing these differences. The issue is classified under [CWE-203: Observable Discrepancy]. Directus versions prior to 11.13.0 are affected, and version 11.13.0 resolves the issue.
Critical Impact
Authenticated low-privilege users can enumerate the existence of restricted collections in a Directus instance, exposing schema information that supports further targeted attacks.
Affected Products
- Monospace Directus versions prior to 11.13.0
- Directus Node.js distributions matching cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:*
- Self-hosted and cloud Directus deployments exposing the REST API
Discovery Timeline
- 2025-11-13 - CVE-2025-64749 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-64749
Vulnerability Analysis
The Directus REST API applies collection existence and authorization checks in separate stages. When a client requests /items/{collection}, middleware first verifies that the collection is defined in the schema, then permission logic evaluates whether the requesting user can access it. Because these two checks emit different error responses, an attacker can distinguish between a collection that exists but is blocked by permissions and one that does not exist at all. Repeated requests with candidate collection names allow enumeration of the hidden schema.
This information disclosure violates the principle that unauthorized users should receive uniform responses regardless of whether the underlying resource exists. Exposed collection names can reveal internal data models, feature flags, or sensitive business entities that guide follow-on attacks against authorization gaps or injection vectors.
Root Cause
The collectionExists middleware in api/src/middleware/collection-exists.ts threw a generic ForbiddenError when a collection was missing from req.schema.collections, while the permissions layer produced a differently structured forbidden error for accessible-but-restricted collections. The two divergent error paths created an observable discrepancy [CWE-203] that leaked existence information.
Attack Vector
Exploitation requires network access to the Directus REST API and a valid low-privilege account. An attacker iterates over candidate collection names and compares the response bodies or error signatures returned by /items/{collection}. No user interaction is required, and the attack complexity is low.
// Patch: api/src/middleware/collection-exists.ts
import type { RequestHandler } from 'express';
import { systemCollectionRows } from '@directus/system-data';
import asyncHandler from '../utils/async-handler.js';
import { createCollectionForbiddenError } from '../permissions/modules/process-ast/utils/validate-path/create-error.js';
const collectionExists: RequestHandler = asyncHandler(async (req, _res, next) => {
if (!req.params['collection']) return next();
if (req.params['collection'] in req.schema.collections === false) {
throw createCollectionForbiddenError('', req.params['collection']);
}
req.collection = req.params['collection'];
});
Source: Directus commit f99c9b8. The patch replaces the generic ForbiddenError with createCollectionForbiddenError, unifying the error response so nonexistent and unauthorized collections return the same structure.
Detection Methods for CVE-2025-64749
Indicators of Compromise
- Repeated GET requests to /items/{collection} from a single authenticated session iterating through varied or dictionary-style collection names.
- Elevated volumes of 403 Forbidden responses from the Directus REST API within short time windows.
- Requests targeting collection names that do not correspond to the user's assigned roles or documented workflows.
Detection Strategies
- Compare response fingerprints from /items/{collection} across accounts to identify divergent error messaging tied to schema enumeration.
- Baseline normal per-user API call patterns and alert on statistically anomalous fan-out across distinct collection names.
- Correlate API access logs with role assignments to flag users probing collections outside their permitted scope.
Monitoring Recommendations
- Enable verbose request logging on the Directus API gateway or reverse proxy, capturing URI, user ID, and response code.
- Forward Directus API logs to a centralized SIEM for correlation with authentication and permission events.
- Track error-rate spikes per authenticated principal and alert when thresholds exceed a defined baseline.
How to Mitigate CVE-2025-64749
Immediate Actions Required
- Upgrade all Directus deployments to version 11.13.0 or later.
- Audit existing user roles and revoke unnecessary API access, especially for accounts with broad /items/* reach.
- Review recent API access logs for evidence of collection enumeration prior to patching.
Patch Information
Directus version 11.13.0 fixes the vulnerability by unifying the error response returned by the collectionExists middleware. Details are documented in GitHub Security Advisory GHSA-cph6-524f-3hgr and the corresponding remediation commit.
Workarounds
- Place a reverse proxy or API gateway in front of Directus that normalizes /items/{collection} error responses to a single generic message.
- Restrict Directus API access to trusted networks or authenticated service accounts to reduce the pool of potential enumerators.
- Apply strict rate limiting on /items/* endpoints to slow brute-force enumeration attempts.
# Example: upgrade Directus via npm to the patched release
npm install directus@11.13.0
# Verify the installed version
npx directus --version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.