CVE-2024-54128: Monospace Directus
Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.
Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making the application vulnerable to HTML Injection. This vulerability is fixed in 10.13.4 and 11.2.0.
Affected products
- Monospace Directus: from 10.10.0, before 10.13.4 (fixed in 10.13.4); from 11.0.0, before 11.2.2 (fixed in 11.2.2)
Published 2024-12-05. Last modified 2026-06-17.