CVE-2025-64748: Monospace Directus

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11.13.0 allows authenticated users to search concealed/sensitive fields when they have read permissions. While actual values remain masked (`****`), successful matches can be detected through returned records, enabling enumeration attacks on sensitive data. Version 11.13.0 fixes the issue.

Affected products

  • Monospace Directus: before 11.13.0 (fixed in 11.13.0)

Published 2025-11-13. Last modified 2026-06-17.