Home

Description

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.

PUBLISHED Reserved 2025-11-18 | Published 2025-12-08 | Updated 2025-12-08 | Assigner mitre

References

memos.com

usememos.com

github.com/usememos/memos/pull/5217

herolab.usd.de/security-advisories/usd-2025-0060/

cve.org (CVE-2025-65796)

nvd.nist.gov (CVE-2025-65796)

Download JSON