CVE-2026-10716
Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with geometry but contains attacker-controlled SQL syntax after the geometry subtype.This issue affects Directus: before 12.1.0.
| CWE | CWE-89 |
| Vendor | directus |
| Product | directus |
| Published | Aug 5, 2026 |
| Last Updated | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for directus directus
Be the first to know when new unknown vulnerabilities affecting directus directus are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Directus / Directus
0 < 12.1.0
References
Credits
Santiago Alvarez Oscar Naveda