In Directus, when a Flow with the "Webhook" trigger and the "Data of Last Operation" response body encounters a ValidationError thrown by a failed condition operation, the API response includes sensitive data. This includes environmental variables, sensitive API keys, user accountability information, and operational data.
This issue poses a significant security risk, as any unintended exposure of this data could lead to potential misuse.
Steps to Reproduce:
$env)$accountabilityExpected Behavior: In the event of a ValidationError, the API response should only contain relevant error messages and details, avoiding the exposure of sensitive data.
Actual Behavior: The API response includes sensitive information such as:
FLOWS_ENV_ALLOW_LIST)role, user, etc.)current_payments, $last), which might contain private details.{
"cwe_ids": [
"CWE-200"
],
"github_reviewed": true,
"github_reviewed_at": "2025-03-26T20:08:58Z",
"nvd_published_at": "2025-03-26T18:15:27Z",
"severity": "HIGH"
}