{"id":"GHSA-8m32-p958-jg99","summary":"Directus: Missing Cross-Origin Opener Policy","details":"## Summary\n\nDirectus's Single Sign-On (SSO) login pages lacked a `Cross-Origin-Opener-Policy` (COOP) HTTP response header. Without this header, a malicious cross-origin window that opens the Directus login page retains the ability to access and manipulate the `window` object of that page. An attacker can exploit this to intercept and redirect the OAuth authorization flow to an attacker-controlled OAuth client, causing the victim to unknowingly grant access to their authentication provider account (e.g. Google, Discord).\n\n## Impact\n\nA successful attack allows the attacker to obtain an OAuth access token for the victim's third-party identity provider account. Depending on the scopes authorized, this can lead to:\n- Unauthorized access to the victim's linked identity provider account\n- Account takeover of the Directus instance if the attacker can authenticate using the stolen credentials or provider session\n\n## Patches\n\nThis issue has been addressed by adding the `Cross-Origin-Opener-Policy: same-origin` HTTP response header to SSO-related endpoints. This header instructs the browser to place the page in its own browsing context group, severing any reference the opener window may hold.\n\n## Workarounds\n\nUsers who are unable to upgrade immediately can mitigate this vulnerability by configuring their reverse proxy or web server to add the following HTTP response header to all Directus responses: `Cross-Origin-Opener-Policy: same-origin`","aliases":["CVE-2026-35408"],"modified":"2026-04-07T14:35:36.193204Z","published":"2026-04-04T06:06:00Z","database_specific":{"nvd_published_at":"2026-04-06T22:16:21Z","cwe_ids":["CWE-346","CWE-693"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-04-04T06:06:00Z"},"references":[{"type":"WEB","url":"https://github.com/directus/directus/security/advisories/GHSA-8m32-p958-jg99"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35408"},{"type":"PACKAGE","url":"https://github.com/directus/directus"}],"affected":[{"package":{"name":"directus","ecosystem":"npm","purl":"pkg:npm/directus"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"11.17.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-8m32-p958-jg99/GHSA-8m32-p958-jg99.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"}]}