Path Traversal Vulnerability in usememos: Attachment Service
CVE-2025-65799

4.3MEDIUM

Key Information:

Vendor

usememos

Status
Vendor
CVE Published:
8 December 2025

What is CVE-2025-65799?

A vulnerability in the usememos memos application version 0.25.2 arises from inadequate file name validation in the Attachment service, potentially enabling attackers to conduct path traversal attacks. This flaw allows unauthorized access to sensitive files within the system, posing significant security risks for users. It is crucial for customers to apply appropriate security measures and updates to safeguard their data.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.