Usememos
Usememos Memos: vulnerabilidades y CVE
Usememos Memos tiene 80 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE80
Últimos 12 meses13
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-84203 | Alta (8.6) | 0.45% | — | 1 sept 2026 | Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC… |
| CVE-2026-82476 | Media (6.9) | 0.43% | — | 29 ago 2026 | Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers can make the server… |
| CVE-2026-75110 | Crítica (9.3) | 0.66% | — | 17 ago 2026 | MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset, the… |
| CVE-2026-71272 | Alta (8.5) | 0.26% | — | 5 ago 2026 | Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.DefaultResolver.LookupHost and validates the resulting IPs against reserved ranges, but then dials… |
| CVE-2026-71271 | Alta (8.5) | 0.33% | — | 5 ago 2026 | Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified — unlike the correctly implemented… |
| CVE-2026-30586 | Media (6.1) | 0.31% | — | 2 jun 2026 | Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Memo Rendering Component, and Public/Private Memo View pages |
| CVE-2026-6634 | Baja (2.1) | 0.35% | — | 20 abr 2026 | A weakness has been identified in usememos memos up to 0.22.1. This affects the function memos_access_token of the file src/App.tsx of the component UpdateInstanceSetting. This manipulation of the argument… |
| CVE-2025-65799 | Media (4.3) | 0.21% | — | 8 dic 2025 | A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal. |
| CVE-2025-65797 | Media (6.5) | 0.28% | — | 8 dic 2025 | Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account… |
| CVE-2025-65795 | Alta (7.5) | 0.26% | — | 8 dic 2025 | Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request. |
| CVE-2025-65798 | Media (5.4) | 0.18% | — | 8 dic 2025 | Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users. |
| CVE-2025-65796 | Media (4.3) | 0.20% | — | 8 dic 2025 | Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos. |
| CVE-2024-21635 | Alta (7.1) | 0.29% | — | 14 nov 2025 | Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their password, the existing list of Access Tokens stay valid instead of… |
| CVE-2025-56761 | Media (5.4) | 0.26% | — | 3 sept 2025 | Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serve it back as is. An… |
| CVE-2025-56760 | Media (4.3) | 0.35% | — | 3 sept 2025 | When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server. |
| CVE-2025-50738 | Crítica (9.8) | 2.2% | — | 29 jul 2025 | The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without… |
| CVE-2025-22952 | Crítica (9.8) | 2.9% | — | 27 feb 2025 | elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks. |
| CVE-2023-0109 | Media (5.4) | 0.44% | — | 15 nov 2024 | A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an… |
| CVE-2024-41659 | Alta (8.1) | 0.64% | — | 20 ago 2024 | memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may… |
| CVE-2024-29029 | Media (6.1) | 1.1% | — | 19 abr 2024 | memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The… |
| CVE-2024-29030 | Media (5.3) | 1.1% | — | 19 abr 2024 | memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos… |
| CVE-2024-29028 | Media (5.3) | 1.0% | — | 19 abr 2024 | memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited… |
| CVE-2023-5036 | Alta (8.8) | 0.32% | — | 18 sept 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1. |
| CVE-2023-4698 | Alta (7.5) | 0.92% | — | 1 sept 2023 | Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2. |
| CVE-2023-4697 | Alta (8.8) | 0.85% | — | 1 sept 2023 | Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2. |
| CVE-2023-4696 | Crítica (9.8) | 1.1% | — | 1 sept 2023 | Improper Access Control in GitHub repository usememos/memos prior to 0.13.2. |
| CVE-2022-25978 | Media (6.1) | 0.53% | — | 15 feb 2023 | All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with… |
| CVE-2023-0112 | Media (5.4) | 0.57% | — | 7 ene 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. |
| CVE-2023-0111 | Media (5.4) | 0.50% | — | 7 ene 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. |
| CVE-2023-0110 | Media (5.4) | 0.50% | — | 7 ene 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.