Junglewise Threat Intelligence

CVE-2025-65795: usememos memos incorrect access control in user registration API

CVE-2025-65795 · Severity: high · CVSS 7.5 · Published 2025-12-08

Technologies: github.com/usememos/memos (Go), Usememos Memos. Vendors: Go, Usememos.

Executive brief

A vulnerability in the Memos note-taking application allows unauthorized individuals to create new user accounts even when the administrator has disabled public registration. This flaw bypasses intended security settings, potentially allowing attackers to gain a foothold in the system. Once an account is created, it can be used as a starting point for further attacks, such as unauthorized data access or system compromise.

Technical details

A broken access control vulnerability exists in the REST API of usememos memos v0.25.2. The application fails to enforce the 'Disallow user registration' administrative setting within the `/api/v1/users` endpoint. An unauthenticated remote attacker can bypass the frontend registration restrictions by sending a direct POST request to the API with a chosen username and password. This allows for unauthorized account creation, which can subsequently be leveraged to perform authenticated-only attacks, such as arbitrary file writes or account takeovers. The issue was addressed in version 0.25.3 by adding authorization checks to the user registration service.

Affected products

  • usememos memos 0.25.2

Timeline

  • 2025-11-03: disclosed: First contact with vendor by researcher
  • 2025-11-04: other: Pull request submitted
  • 2025-11-06: patched: Fix merged to main branch
  • 2025-11-25: other: Version 0.25.3 released
  • 2025-12-03: advisory: Researcher advisory published
  • 2025-12-08: other: CVE published to NVD

References

Related threats