-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing user status checks during session token validation. While the actual patch adds session clearing mechanisms (clearUserSessions) and accountability tracking, the core vulnerability exists in verifySessionJWT which wasn't modified in the provided diff but is explicitly called out in the advisory. Runtime detection would focus on the token verification flow where user status isn't validated, making verifySessionJWT the primary vulnerable function visible in call stacks during exploitation.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| directus | npm | >= 10.10.0, < 11.15.0 | 11.15.0 |
Ongoing coverage of React2Shell