CVE-2019-13981: Rangerstudio Directus 7 API
Medium severity, CVSS 5.3. EPSS: 1.5% chance of exploitation in the next 30 days.
In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ directory. This is related to a configuration option in which the file collection can be non-public, but this option does not apply to the thumbnailer.
Affected products
- Rangerstudio Directus 7 API: up to and including 2.3.0
Published 2019-07-19. Last modified 2026-06-17.