← Back to browse · API

CVE-2026-10716

Severity
-
CVSS
-
Published
2026-08-05
Modified
2026-08-05
First seen
2026-08-06
Aliases
-
Products
-
Sources
nvd CVE-2026-10716

Description

Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with geometry but contains attacker-controlled SQL syntax after the geometry subtype.This issue affects Directus: before 12.1.0.

References