CVE-2025-65798: Medium severity npm/usememos vulnerability
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/usememos/memosto a version that resolves this vulnerability.Fixed in 0.25.3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65798?
CVE-2025-65798 is considered a critical vulnerability due to its potential to allow unauthorized modification or deletion of attachments by users with low-level privileges.
How do I fix CVE-2025-65798?
To fix CVE-2025-65798, upgrade to version 0.25.3 of the usememos memos software.
What software is affected by CVE-2025-65798?
CVE-2025-65798 affects usememos memos version 0.25.2.
What type of vulnerability is CVE-2025-65798?
CVE-2025-65798 is an access control vulnerability that allows improper access by low-level privilege users.
Can CVE-2025-65798 lead to data loss?
Yes, CVE-2025-65798 can lead to data loss as it allows attackers to delete attachments made by other users.