PT-2025-49567 · Unknown · Usememos/Memos

Published

2025-12-08

·

Updated

2026-01-06

·

CVE-2025-65798

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions usememos memos version 0.25.2
Description A flaw in access control within usememos memos allows attackers with limited privileges to improperly change or remove attachments uploaded by other users. The issue involves insufficient restrictions on user permissions related to attachment management.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-65798
GHSA-8P44-G572-557H
GO-2025-4216
SUSE-SU-2026:0037-1

Affected Products

Usememos/Memos