
CVE-2026-39942 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_d… https://www.cve.org/CVERecord?id=CVE-2026-39942
Post summary
The post announces CVE-2026-39942 in Directus, detailing a user‑controlled filename flaw in the PATCH /files/{id} endpoint before version 11.17.0, and notes that the vulnerability has been patched in newer releases.

