github.com/usememos/memos
Go74 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/usememos/memospage 2 of 2
- CVE-2023-0108MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.10.02023-01-07
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- CVE-2023-0109MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.10.02024-11-15
A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HT…
- CVE-2023-0110MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.10.02023-01-07
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- CVE-2023-0111MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.10.02023-01-07
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- CVE-2023-0112MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.10.02023-01-07
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- CVE-2023-4696CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.13.22023-09-01
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
- CVE-2023-4697HIGHCVSS 8.8EG 8.8✓ Fixed in 0.13.22023-09-01
Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.
- CVE-2023-4698HIGHCVSS 7.5EG 7.52023-09-01
Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.
- CVE-2023-5036HIGHCVSS 8.8EG 8.8✓ Fixed in 0.15.12023-09-18
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.
- CVE-2024-21635HIGHCVSS 7.5EG 7.52025-11-14
Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their password, the existing list of Access Tokens stay valid instead of expiring. If a user finds th…
- CVE-2024-29028MEDIUMCVSS 5.8EG 5.8✓ Fixed in 0.16.12024-04-19
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json for…
- CVE-2024-29029MEDIUMCVSS 6.1EG 6.1✓ Fixed in 0.22.02024-04-19
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the ima…
- CVE-2024-29030MEDIUMCVSS 5.8EG 5.8✓ Fixed in 0.22.02024-04-19
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable…
- CVE-2024-41659HIGHCVSS 8.1EG 8.1✓ Fixed in 0.21.02024-08-20
memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking web…
- CVE-2025-22952CRITICALCVSS 9.8EG 9.82025-02-27
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.
- CVE-2025-50738CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.24.42025-07-29
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user conse…
- CVE-2025-56760MEDIUMCVSS 4.3EG 4.32025-09-03
When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server.
- CVE-2025-56761MEDIUMCVSS 5.4EG 5.42025-09-03
Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serve it back as is. An authenticated attacker…
- CVE-2025-65795HIGHCVSS 7.5EG 7.5✓ Fixed in 0.25.32025-12-08
Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.
- CVE-2025-65796MEDIUMCVSS 4.3EG 4.3✓ Fixed in 0.25.32025-12-08
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.
- CVE-2025-65797MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.25.32025-12-08
Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Servi…
- CVE-2025-65798MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.25.32025-12-08
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.
- CVE-2025-65799MEDIUMCVSS 4.3EG 4.3✓ Fixed in 0.25.32025-12-08
A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.
- CVE-2026-6634MEDIUMCVSS 6.3EG 6.32026-04-20
A weakness has been identified in usememos memos up to 0.22.1. This affects the function memos_access_token of the file src/App.tsx of the component UpdateInstanceSetting. This manipulation of the argument additionalStyle/additionalScript …
Check whether github.com/usememos/memos is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/usememos/memos CVEs against the assets you own.
Start Free Scan →