CVE-2025-65799: Path Traversal
A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/usememos/memosto a version that resolves this vulnerability.Fixed in 0.25.3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65799?
CVE-2025-65799 has been classified as a high severity vulnerability due to its potential to allow path traversal attacks.
How do I fix CVE-2025-65799?
To mitigate CVE-2025-65799, update the usememos memos software to version 0.25.3 or later.
What causes CVE-2025-65799 vulnerability?
CVE-2025-65799 is caused by a lack of file name validation or verification in the Attachment service.
Which versions of the usememos memos software are affected by CVE-2025-65799?
CVE-2025-65799 affects version 0.25.2 of the usememos memos software.
What type of attack can CVE-2025-65799 facilitate?
CVE-2025-65799 can facilitate path traversal attacks, allowing unauthorized access to the file system.