CVE-2023-4698

HIGH

memos < 0.13.2 - Improper Input Validation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-4698. PoCs published by mnqazi.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2023-4698, an LFI vulnerability in usememos/memos < 0.13.2. It explains the root cause, impact, and vulnerable code in 'resource.go' where the 'InternalPath' parameter is inadequately sanitized.

Description

Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.

Exploits (1)

nomisec WRITEUP
by mnqazi · poc
https://github.com/mnqazi/CVE-2023-4698

This repository provides a detailed technical analysis of CVE-2023-4698, an LFI vulnerability in usememos/memos < 0.13.2. It explains the root cause, impact, and vulnerable code in 'resource.go' where the 'InternalPath' parameter is inadequately sanitized.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: usememos/memos < 0.13.2
No auth needed
Prerequisites: Access to the vulnerable endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 7.5
EPSS 0.0189
EPSS Percentile 83.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
usememos/memos < 0.13.2
usememos/memos 0Go
Published Sep 01, 2023
Tracked Since Feb 18, 2026