Vulnerabilities/

Suspended Directus user can continue to use session token to access API

Severity:
Low

Description

Since the user status is not checked when verifying a session token a suspended user can use the token generated in session auth mode to access the API despite their status.

Recommendation

Update the @directus/types package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@directus/types
Anything's wrong? Let us know Last updated on June 09, 2025