{"id":"GHSA-q75c-4gmv-mg9x","summary":"Directus: Open Redirect in Admin 2FA Setup Page","details":"### Summary\n\nDirectus is vulnerable to an Open Redirect via the redirect query parameter on the `/admin/tfa-setup` page. When an administrator who has not yet configured Two-Factor Authentication (2FA) visits a crafted URL, they are presented with the legitimate Directus 2FA setup page. After completing the setup process, the application redirects the user to the attacker-controlled URL specified in the `redirect` parameter without any validation.\n\nThis vulnerability could be used in phishing attacks targeting Directus administrators, as the initial interaction occurs on a trusted domain.\n\n### Credits\nDiscovered by Neo by ProjectDiscovery (https://neo.projectdiscovery.io/)","aliases":["CVE-2026-35411"],"modified":"2026-04-07T14:43:44.420545Z","published":"2026-04-04T06:08:26Z","database_specific":{"github_reviewed_at":"2026-04-04T06:08:26Z","nvd_published_at":"2026-04-06T22:16:22Z","cwe_ids":["CWE-601"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/directus/directus/security/advisories/GHSA-q75c-4gmv-mg9x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35411"},{"type":"PACKAGE","url":"https://github.com/directus/directus"}],"affected":[{"package":{"name":"directus","ecosystem":"npm","purl":"pkg:npm/directus"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"11.16.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-q75c-4gmv-mg9x/GHSA-q75c-4gmv-mg9x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}