{"id":"GHSA-393c-p46r-7c95","summary":"Directus: Path Traversal and Broken Access Control in File Management API","details":"## Summary\n\nA broken access control vulnerability was identified in the Directus file management API that allows authenticated users to overwrite files belonging to other users by manipulating the `filename_disk` parameter.\n\n## Details\n\nThe `PATCH /files/{id}` endpoint accepts a user-controlled `filename_disk` parameter. By setting this value to match the storage path of another user's file, an attacker can overwrite that file's content while manipulating metadata fields such as `uploaded_by` to obscure the tampering.\n\n## Impact\n\n- **Unauthorized File Overwrite**: Attackers can replace legitimate files with malicious content, creating significant risk of malware propagation and data corruption.\n- **Remote Code Execution**: If the storage backend is shared with the extensions location, attackers can deploy malicious extensions that execute arbitrary code when loaded.\n- **Data Integrity Compromise**: Files can be tampered with or replaced without visible indication in the application interface.\n\n## Mitigation\n\nThe `filename_disk` parameter should be treated as a server-controlled value. Uniqueness of storage paths must be enforced server-side, and `filename_disk` should be excluded from the fields users are permitted to update directly.","aliases":["CVE-2026-39942"],"modified":"2026-04-09T19:18:35.599562Z","published":"2026-04-04T06:06:39Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-04-04T06:06:39Z","nvd_published_at":"2026-04-09T17:16:29Z","cwe_ids":["CWE-284","CWE-639","CWE-915"]},"references":[{"type":"WEB","url":"https://github.com/directus/directus/security/advisories/GHSA-393c-p46r-7c95"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39942"},{"type":"PACKAGE","url":"https://github.com/directus/directus"},{"type":"WEB","url":"https://github.com/directus/directus/releases/tag/v11.17.0"}],"affected":[{"package":{"name":"directus","ecosystem":"npm","purl":"pkg:npm/directus"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"11.17.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-393c-p46r-7c95/GHSA-393c-p46r-7c95.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N"}]}