Access Control Flaw in Memos by usememos Enables Unauthorized Modifications
CVE-2025-65797

6.5MEDIUM

Key Information:

Vendor

usememos

Status
Vendor
CVE Published:
8 December 2025

What is CVE-2025-65797?

The Memos product by usememos is impacted by an access control vulnerability in its Identity Provider service. This flaw allows attackers with minimal privileges to manipulate or remove registered identity providers indiscriminately. Such actions can lead to significant security risks, including the potential for account takeover and Denial of Service (DoS) incidents, jeopardizing the integrity of user accounts and the overall functionality of the service.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.