AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-30353

HIGH · CVSS 8.6 EPSS 0.51% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-03-26 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.6. Public exploit code or proof-of-concept references have been detected in its references.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-30353
Severity
HIGH
CVSS
8.6
EPSS
0.51%

Original NVD Description

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.5.0, when a Flow with the "Webhook" trigger and the "Data of Last Operation" response body encounters a ValidationError thrown by a failed condition operation, the API response includes sensitive data. This includes environmental variables, sensitive API keys, user accountability information, and operational data. This issue poses a significant security risk, as any unintended exposure of this data could lead to potential misuse. Version 11.5.0 fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)