directus is vulnerable to Path Traversal
68
Medium Risk
The Mail Service resolves email template names by joining the caller-supplied template value onto the templates directory with path.resolve, which collapses traversal segments and never confirms the result stays inside the templates root. A user who can configure a Flow Send Email operation can supply a relative name that escapes the root, causing the Liquid engine to read and render an arbitrary host file into the email body. This discloses environment files, credentials, and other host configuration, and weakens tenant isolation in shared-hosting deployments. The fix restricts resolved template paths to the configured templates directories.
You are affected if you are using a version that falls within the vulnerable range and you use Flows with a Send Email operation.
directus is vulnerable to Path Traversal in versions 0.0.1 - 12.0.2.
Upgrade the directus library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant