{"id":"GHSA-x3vm-88hf-gpxp","summary":"Directus is vulnerable to sensitive data exposure as user data is not being redacted when logged","details":"### Summary\n\nWhen using Directus Flows to handle CRUD events for users it is possible to log the incoming data to console using the \"Log to Console\" operation and a template string. \n\n### Impact\n\nMalicious admins can log sensitive data from other users when they are created or updated.\n\n### Workarounds\nAvoid logging sensitive data to the console outside the context of development.","aliases":["CVE-2025-53885"],"modified":"2025-07-15T16:27:18.997140Z","published":"2025-07-15T15:18:06Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-07-15T15:18:06Z","nvd_published_at":"2025-07-15T00:15:23Z","cwe_ids":["CWE-532"]},"references":[{"type":"WEB","url":"https://github.com/directus/directus/security/advisories/GHSA-x3vm-88hf-gpxp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53885"},{"type":"WEB","url":"https://github.com/directus/directus/pull/25355"},{"type":"WEB","url":"https://github.com/directus/directus/commit/859f664f56fb50401c407b095889cea38ff580e5"},{"type":"PACKAGE","url":"https://github.com/directus/directus"},{"type":"WEB","url":"https://github.com/directus/directus/releases/tag/v11.9.0"}],"affected":[{"package":{"name":"directus","ecosystem":"npm","purl":"pkg:npm/directus"},"ranges":[{"type":"SEMVER","events":[{"introduced":"9.0.0"},{"fixed":"11.9.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-x3vm-88hf-gpxp/GHSA-x3vm-88hf-gpxp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N"}]}