directus is vulnerable to Cross-Site WebSocket Hijacking (CSWSH)
81
High Risk
The WebSocket upgrade handler accepts cross-origin upgrade requests carrying the session cookie without validating the handshake Origin, and the upgrade path bypasses the CORS middleware used by the REST and GraphQL transports. A browser attaches the session cookie automatically, so a page on an untrusted origin can open a WebSocket that is authenticated as the visiting user. Over that connection it can read, create, update, and delete records in any collection the victim can access, extending to system collections when the victim is an administrator. The fix enforces an allowed-origin check on WebSocket connections.
You are affected if you are using a version that falls within the vulnerable range and you have WebSockets enabled and rely on session-cookie authentication.
directus is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) in versions 10.10.5 - 12.0.2.
Upgrade the directus library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant