4.3

CVE-2025-56760

Exploit
When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Usememos ≫ Memos Version 0.22.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.27
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-24 Path Traversal: '../filedir'

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.

https://github.com/usememos/memos/blob/v0.24.4/server/router/api/v1/resource_service.go#L48
Product
https://www.sonarsource.com/blog/securing-go-applications-with-sonarqube-real-world-examples/
Patch
Third Party Advisory
Exploit