CVE-2024-6533: Monospace Directus
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client. This is possible because the application injects an attacker-controlled parameter that will be stored in the server and used by the client into an unsanitized DOM element. When chained with CVE-2024-6534, it could result in account takeover.
Affected products
- Monospace Directus: version 10.13.0 only
Published 2024-08-15. Last modified 2026-06-17.