CVE-2026-84203
- EPSS 0.26%
- Veröffentlicht 01.09.2026 15:18:58
- Zuletzt bearbeitet 08.09.2026 20:18:59
Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens an...
CVE-2026-82476
- EPSS 0.25%
- Veröffentlicht 29.08.2026 16:35:36
- Zuletzt bearbeitet 10.09.2026 15:53:23
Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers can make the server request internal hosts in that r...
CVE-2026-71272
- EPSS 0.17%
- Veröffentlicht 05.08.2026 12:26:19
- Zuletzt bearbeitet 26.08.2026 17:13:24
Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.DefaultResolver.LookupHost and validates the resulting IPs against reserved ranges, but then dials net.JoinHostPort(host, port) using ...
CVE-2026-71271
- EPSS 0.24%
- Veröffentlicht 05.08.2026 12:26:18
- Zuletzt bearbeitet 26.08.2026 17:13:24
Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified — unlike the correctly implemented sibling function isInternalIP in i...
CVE-2026-30586
- EPSS 0.22%
- Veröffentlicht 02.06.2026 00:00:00
- Zuletzt bearbeitet 22.07.2026 19:10:00
Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Memo Rendering Component, and Public/Private Memo View pages
CVE-2026-6634
- EPSS 0.25%
- Veröffentlicht 20.04.2026 11:30:13
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in usememos memos up to 0.22.1. This affects the function memos_access_token of the file src/App.tsx of the component UpdateInstanceSetting. This manipulation of the argument additionalStyle/additionalScript causes impr...
CVE-2025-65796
- EPSS 0.19%
- Veröffentlicht 08.12.2025 00:00:00
- Zuletzt bearbeitet 05.07.2026 17:17:23
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.
CVE-2025-65798
- EPSS 0.18%
- Veröffentlicht 08.12.2025 00:00:00
- Zuletzt bearbeitet 05.07.2026 17:17:24
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.
CVE-2025-65795
- EPSS 0.25%
- Veröffentlicht 08.12.2025 00:00:00
- Zuletzt bearbeitet 05.07.2026 17:17:23
Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.
CVE-2025-65797
- EPSS 0.27%
- Veröffentlicht 08.12.2025 00:00:00
- Zuletzt bearbeitet 05.07.2026 17:17:24
Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS).