PT-2025-49566 · Unknown · Usememos/Memos

Published

2025-12-08

·

Updated

2026-01-06

·

CVE-2025-65797

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions usememos memos version 0.25.2
Description A flaw exists in the Identity Provider service of usememos memos that involves incorrect access control. Attackers with limited privileges can modify or delete registered identity providers. This can lead to account takeover or a Denial of Service (DoS) condition. The affected component is the Identity Provider service.
Recommendations Update usememos memos to a newer version that addresses this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

LPE

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-65797
GHSA-99M2-QWX6-2W6F
GO-2025-4220
SUSE-SU-2026:0037-1

Affected Products

Usememos/Memos