Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with geometry but contains attacker-controlled SQL syntax after the geometry subtype.This issue affects Directus: before 12.1.0.

Project Subscriptions

Vendors Products
Directus Subscribe
Directus Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with geometry but contains attacker-controlled SQL syntax after the geometry subtype.This issue affects Directus: before 12.1.0.
Title Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation
First Time appeared Directus
Directus directus
Weaknesses CWE-89
CPEs cpe:2.3:a:directus:directus:*:*:linux:*:*:*:*:*
cpe:2.3:a:directus:directus:*:*:macos:*:*:*:*:*
cpe:2.3:a:directus:directus:*:*:windows:*:*:*:*:*
Vendors & Products Directus
Directus directus
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-08-05T17:45:11.813Z

Reserved: 2026-06-02T19:25:29.287Z

Link: CVE-2026-10716

cve-icon Vulnrichment

Updated: 2026-08-05T17:38:42.865Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T18:30:16Z

Weaknesses