Executive brief
Memos is a self-hosted note-taking application used for personal knowledge management and daily logs. A security flaw in the application's reaction system allows any logged-in user to delete reactions (such as emojis or likes) posted by other users on any memo. While this does not expose private note content, it allows malicious users to tamper with social interactions and engagement data within the platform.
Technical details
A broken access control vulnerability (CWE-284/CWE-862) exists in the Reaction service of Memos v0.25.2. The application fails to validate if the user requesting the deletion of a reaction is the actual owner of that reaction. An authenticated attacker can exploit this by sending a DELETE request to the `/api/v1/reactions/<NumericIdOfReaction>` endpoint. By supplying the ID of a reaction belonging to another user, the attacker can successfully remove it from the system. The issue was addressed in pull request #5217 by adding owner-check authorization logic and was officially fixed in version 0.25.3.
Affected products
- usememos memos 0.25.2
Timeline
- 2025-11-03: disclosed: First contact with vendor
- 2025-11-04: patched: Pull request submitted
- 2025-11-06: patched: Commit merged to main branch
- 2025-11-25: patched: Version 0.25.3 released
- 2025-12-03: advisory: Third-party advisory published by usd HeroLab
- 2025-12-08: advisory: NVD advisory published