Access Control Weakness in Memos by UseMemos
CVE-2025-65798

5.4MEDIUM

Key Information:

Vendor

UseMemos

Status
Vendor
CVE Published:
8 December 2025

What is CVE-2025-65798?

An access control vulnerability in Memos version 0.25.2 permits users with low-level privileges to make unauthorized modifications or deletions of attachments created by other users. This could lead to data integrity issues and unauthorized manipulation of user content, emphasizing the necessity for robust access management within the application.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.