CVE-2025-65795: High severity npm/usememos vulnerability
Published Dec 8, 2025
·Updated
Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.
Affected Software
3 affected componentsFixes available
npm/usememos
go/github.com/usememos/memos<0.25.3
0.25.3
usememos memos=0.25.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/usememos/memosto a version that resolves this vulnerability.Fixed in 0.25.3
Event History
Dec 8, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:30 PM
Data Sourced
via GitHub·06:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65795?
CVE-2025-65795 is classified as a medium severity vulnerability due to its potential for unauthorized account creation.
2
How do I fix CVE-2025-65795?
To fix CVE-2025-65795, upgrade to usememos version 0.25.3 or later.
3
What causes CVE-2025-65795?
CVE-2025-65795 is caused by incorrect access control in the /api/v1/user endpoint.
4
Who is affected by CVE-2025-65795?
CVE-2025-65795 affects users of usememos memos versions prior to 0.25.3.
5
What can attackers do with CVE-2025-65795?
Attackers can exploit CVE-2025-65795 to create arbitrary user accounts without authorization.