MEDIUM 5.3 npm

Directus' exact version number is exposed by the OpenAPI Spec

GHSA-rmjh-cf9q-pv7q · CVE-2025-53887

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Summary

The exact Directus version number is incorrectly being used as OpenAPI Spec version this means that it is being exposed by the /server/specs/oas endpoint without authentication.

Impact

With the exact version information a malicious attacker can look for known vulnerabilities in Directus core or any of its shipped dependencies in that specific running version.

Ready to move

Start Securing

Free, no credit card | First findings in minutes