GHSA-77qm-wvqq-fg79
Directus vulnerable to unhandled exception on illegal filename_disk value
Quick fix
GHSA-77qm-wvqq-fg79 — directus: upgrade to the fixed version with the command below.
npm install directus@9.15.0Details
The Directus process can be aborted by having an authorized user update the `filename_disk` value to a folder and accessing that file through the `/assets` endpoint.
The vulnerability is patched and released in v9.15.0.
You can prevent this problem by making sure no (untrusted) non-admin users have permissions to update the `filename_disk` field on `directus_files`.
### For more information
If you have any questions or comments about this advisory: * Open a Discussion in [directus/directus](https://github.com/directus/directus/discussions) * Email us at [security@directus.io](mailto:security@directus.io)
### Credits
This vulnerability was first discovered and reported by Witold Gorecki.
Are you affected?
Enter the version of the package you're using.