CVE-2026-6634: usememos UpdateInstanceSetting App.tsx memos_access_token improper authorization
A weakness has been identified in usememos memos up to 0.22.1. This affects the function memosaccesstoken of the file src/App.tsx of the component UpdateInstanceSetting. This manipulation of the argument additionalStyle/additionalScript causes improper authorization. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6634?
CVE-2026-6634 is classified as a medium severity vulnerability due to improper authorization in the memos_access_token function.
How do I fix CVE-2026-6634?
To fix CVE-2026-6634, update usememos memos to version 0.22.2 or later.
What systems are affected by CVE-2026-6634?
CVE-2026-6634 affects all versions of usememos memos up to and including 0.22.1.
What kind of attack can exploit CVE-2026-6634?
CVE-2026-6634 can be exploited through improper authorization, allowing unauthorized access to sensitive functionalities.
Is CVE-2026-6634 a remote or local vulnerability?
CVE-2026-6634 is primarily a remote vulnerability, as it can be exploited over a network by an attacker.