-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing session validation during token verification. The commit adds a new 'verifySessionJWT' check within getAccountabilityForToken, indicating this function was previously incomplete. Before the patch, it only validated JWT cryptographically but didn't verify session state in the database, making it the vulnerable entry point for unrevoked session tokens.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| directus | npm | >= 10.10.0, < 10.11.0 | 10.11.0 |
Ongoing coverage of React2Shell