CVE-2025-65796: Medium severity npm/usememos vulnerability
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/usememos/memosto a version that resolves this vulnerability.Fixed in 0.25.3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65796?
CVE-2025-65796 is classified as a high-severity vulnerability due to its potential impact on user data integrity.
How do I fix CVE-2025-65796?
To fix CVE-2025-65796, upgrade usememos memos to version 0.25.3 or later.
Who is affected by CVE-2025-65796?
CVE-2025-65796 affects users of the usememos memos software version 0.25.2.
What kind of attack does CVE-2025-65796 facilitate?
CVE-2025-65796 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.
When was CVE-2025-65796 identified?
CVE-2025-65796 was identified recently and is under active scrutiny for its security implications.