Go Package Vulnerabilities
Vulnerabilities associated with github.com/usememos/memos.
Packages
Clear package- github.com/mattermost/mattermost/server/v8199 vulnerabilities
- github.com/mattermost/mattermost-server178 vulnerabilities
- code.gitea.io/gitea94 vulnerabilities
- gogs.io/gogs76 vulnerabilities
- github.com/usememos/memos74 vulnerabilities
- github.com/grafana/grafana61 vulnerabilities
- github.com/rancher/rancher61 vulnerabilities
- github.com/siyuan-note/siyuan/kernel58 vulnerabilities
- github.com/hashicorp/vault55 vulnerabilities
- github.com/traefik/traefik/v253 vulnerabilities
- github.com/traefik/traefik/v352 vulnerabilities
- github.com/mattermost/mattermost-server/v647 vulnerabilities
- github.com/filebrowser/filebrowser/v243 vulnerabilities
- k8s.io/kubernetes43 vulnerabilities
- github.com/zitadel/zitadel41 vulnerabilities
- github.com/argoproj/argo-cd/v237 vulnerabilities
- github.com/cilium/cilium37 vulnerabilities
- github.com/docker/docker36 vulnerabilities
- github.com/answerdev/answer34 vulnerabilities
- github.com/argoproj/argo-cd34 vulnerabilities
- github.com/hashicorp/nomad34 vulnerabilities
- code.vikunja.io/api33 vulnerabilities
- github.com/hashicorp/consul32 vulnerabilities
- github.com/openbao/openbao29 vulnerabilities
- github.com/traefik/traefik29 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-6634MEDIUM | usememos UpdateInstanceSetting App.tsx memos_access_token improper authorizationA weakness has been identified in usememos memos up to 0.22.1. This affects the function memos_access_token of the file src/App.tsx of the component UpdateInstanceSetting. This manipulation of the argument additionalStyle/additionalScript causes improper authorization. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS5.3v4.0 | EPSS0.252% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-65797MEDIUM | memos vulnerability allows arbitrarily modification or deletion registered identity providersIncorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS). CWE-284Dec 8, 2025 | CVSS6.5v3.1 | EPSS0.274% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-65795HIGH | memos vulnerability allows the creation of arbitrary accountsIncorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request. CWE-284Dec 8, 2025 | CVSS7.5v3.1 | EPSS0.249% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-65796MEDIUM | memos vulnerability allows arbitrarily reactions deletionIncorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos. CWE-284Dec 8, 2025 | CVSS4.3v3.1 | EPSS0.193% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-65799MEDIUM | memos lacks file name validation or verificationA lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal. CWE-73Dec 8, 2025 | CVSS4.3v3.1 | EPSS0.207% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-65798MEDIUM | memos vulnerability allows arbitrarily modification or deletion of attachmentsIncorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users. CWE-284Dec 8, 2025 | CVSS5.4v3.1 | EPSS0.175% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21635HIGH | Memos Access Tokens Stay Valid after User Password ChangeMemos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their password, the existing list of Access Tokens stay valid instead of expiring. If a user finds that their account has been compromised, they can update their password. In versions up to and including 0.18.1, though, the bad actor will still have access to their account because the bad actor's Access Token stays on the list as a valid token. The user will h… CWE-287Nov 14, 2025 | CVSS7.1v4.0 | EPSS0.284% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-56760MEDIUM | Memos Vulnerable to Path Traversal via the CreateResource EndpointWhen Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server. CWE-24Sep 3, 2025 | CVSS4.3v3.1 | EPSS0.343% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-56761MEDIUM | Memos Vulnerable to Stored Cross-Site ScriptingMemos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serve it back as is. An authenticated attacker can use this to elevate their privileges when the stored XSS is viewed by an admin. CWE-79Sep 3, 2025 | CVSS5.4v3.1 | EPSS0.253% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Memos has Cross-Site Scripting (XSS) Vulnerability in Image URLsThe Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or interaction beyond viewing the memo. This can be exploited by an attacker to disclose the viewing user's IP address, browser User-Agent string, and potentially other request-specific information to the attacker-controlled server, leading to information di… | CVSS-v4.0 | EPSS2.08% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX | |
Memos Server-Side Request Forgery (SSRF)elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks. | CVSS-v4.0 | EPSS2.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX | |
CVE-2023-0109MEDIUM | Stored XSS in usememos/memosA stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is accessed, the malicious script is executed. This can lead to the theft of sensitive information, such as login credentials, from users visiting the affected website. The issue has been fixed in version 0.10.0. CWE-79Nov 15, 2024 | CVSS5.4v3.1 | EPSS0.438% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
GHSL-2024-034: memos CORS Misconfiguration in server.gomemos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. This vulnerability is fixed in 0.21.0. CWE-942Aug 20, 2024 | CVSS-v4.0 | EPSS0.643% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
memos vulnerable to an SSRF in /o/get/imagememos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the response of the current server request, causing a reflected XSS vulnerability. Version 0.22.0 of memos removes the vulnerable file. | CVSS-v4.0 | EPSS1.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX | |
CVE-2024-29028MEDIUM | memos vulnerable to an SSRF in /o/get/httpmetamemos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vulnerability is fixed in 0.16.1. | CVSS5.8v3.1 | EPSS1.05% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
memos vulnerable to an SSRF in /api/resourcememos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable file. | CVSS-v4.0 | EPSS1.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX | |
CVE-2023-5036HIGH | Cross-Site Request Forgery (CSRF) in usememos/memosCross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1. CWE-352Sep 18, 2023 | CVSS8.8v3.1 | EPSS0.285% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4697HIGH | Improper Privilege Management in usememos/memosImproper Privilege Management in GitHub repository usememos/memos prior to 0.13.2. CWE-269Sep 1, 2023 | CVSS8.8v3.1 | EPSS0.701% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4698HIGH | Improper Input Validation in usememos/memosImproper Input Validation in GitHub repository usememos/memos prior to 0.13.2. CWE-20Sep 1, 2023 | CVSS7.5v3.1 | EPSS0.759% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4696CRITICAL | Improper Access Control in usememos/memosImproper Access Control in GitHub repository usememos/memos prior to 0.13.2. CWE-284Sep 1, 2023 | CVSS9.8v3.1 | EPSS0.899% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-25978MEDIUM | Cross Site Scripting in usememos/memosAll versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme. CWE-79Feb 15, 2023 | CVSS5.4v3.1 | EPSS0.534% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-0112MEDIUM | Cross-site Scripting (XSS) - Stored in usememos/memosCross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. CWE-79Jan 7, 2023 | CVSS5.4v3.1 | EPSS0.575% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-0108MEDIUM | Cross-site Scripting (XSS) - Stored in usememos/memosCross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. CWE-79Jan 7, 2023 | CVSS5.4v3.1 | EPSS0.519% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-0107MEDIUM | Cross-site Scripting (XSS) - Stored in usememos/memosCross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. CWE-79Jan 7, 2023 | CVSS5.4v3.1 | EPSS0.498% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-0110MEDIUM | Cross-site Scripting (XSS) - Stored in usememos/memosCross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. CWE-79Jan 7, 2023 | CVSS5.4v3.1 | EPSS0.498% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |