Insufficient Token Revocation in Memos by UseMemos
CVE-2026-84203
8.6HIGH
What is CVE-2026-84203?
Versions 0.26.0 to 0.30.0 of Memos fail to properly revoke refresh tokens when a user changes their password. This oversight enables attackers with stolen refresh tokens to continue accessing user accounts by retrieving new access tokens through the RefreshToken RPC. By exploiting this flaw, attackers can circumvent the intended security measures designed to protect user accounts during password changes.
Affected Version(s)
memos 0.26.0 <= 0.30.0
