Executive brief
A vulnerability in the Memos note-taking application allows unauthorized individuals to create new user accounts even when the administrator has disabled public registration. This flaw bypasses intended security settings, potentially allowing attackers to gain a foothold in the system. Once an account is created, it can be used as a starting point for further attacks, such as unauthorized data access or system compromise.
Technical details
A broken access control vulnerability exists in the REST API of usememos memos v0.25.2. The application fails to enforce the 'Disallow user registration' administrative setting within the `/api/v1/users` endpoint. An unauthenticated remote attacker can bypass the frontend registration restrictions by sending a direct POST request to the API with a chosen username and password. This allows for unauthorized account creation, which can subsequently be leveraged to perform authenticated-only attacks, such as arbitrary file writes or account takeovers. The issue was addressed in version 0.25.3 by adding authorization checks to the user registration service.
Affected products
- usememos memos 0.25.2
Timeline
- 2025-11-03: disclosed: First contact with vendor by researcher
- 2025-11-04: other: Pull request submitted
- 2025-11-06: patched: Fix merged to main branch
- 2025-11-25: other: Version 0.25.3 released
- 2025-12-03: advisory: Researcher advisory published
- 2025-12-08: other: CVE published to NVD