Sploitus

CVE-2025-30225

No indexed exploits for CVE-2025-30225 yet

Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0 and prior to version 12.0.1, corresponding to Directus starting in version 9.22.0 and prior to 11.5.0, is vulnerable to asset unavailability after a burst of malformed transformations. When making many malformed transformation requests at once, at some point, all assets are served as 403. This causes denial of assets for all policies of Directus, including Admin and Public. Version 12.0.1 of the `@directus/storage-driver-s3` package, corresponding to version 11.5.0 of Directus, fixes the issue.

Monospace Directus
< 11.5.0
Fix
Available
CVSS 3.1
5.3 MEDIUM
EPSS
0.4% (33th percentile)
Weakness
CWE-770
NVD status
Analyzed
Published
2025-03-26
CVE-2025-30225 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-30225 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-30225 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.