7.7
CVE-2026-61835
- EPSS 0.23%
- Veröffentlicht 15.07.2026 14:16:11
- Zuletzt bearbeitet 28.07.2026 15:47:21
- CVE-Watchlists
- Unerledigt
Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on Directus's file-import-from-URL feature can be bypassed using the address 0.0.0.0 because api/src/request/is-denied-ip.ts treats 0.0.0.0 as a keyword for local interfaces but never blocks the literal address itself. On Linux and macOS, connecting to 0.0.0.0 reaches localhost, so an authenticated user with file-upload rights can make the server fetch internal services through the /files/import endpoint and retrieve the response as a downloadable file. This issue is fixed in version 12.0.0.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.144 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.7 | 3.1 | 4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://github.com/directus/directus/security/advisories/GHSA-j5h6-vqc3-phqh
https://github.com/directus/directus/pull/27606
https://github.com/directus/directus/commit/f75b25fa44b05c6022b20f231c20bc6e50f021d7
https://github.com/directus/directus/releases/tag/v12.0.0