Executive brief
A vulnerability in Memos, a self-hosted note-taking application, allows users with low-level access to modify or delete the system's identity provider settings. This could allow an attacker to lock other users out of the system or redirect login processes to a malicious server to take over administrator accounts. The flaw compromises the integrity of the authentication process and can lead to a total loss of access for legitimate users.
Technical details
A broken access control vulnerability (CWE-862/CWE-284) exists in the Identity Provider (IDP) service of Memos v0.25.2. The application fails to restrict administrative operations on the `/api/v1/identityProviders` endpoint to host/admin users. Authenticated attackers with low-level privileges can send PATCH or DELETE requests to modify or remove OAuth/SSO configurations. Additionally, the client secret for configured IDPs is exposed to unauthenticated users via GET requests. By modifying the IDP configuration to point to a malicious server, an attacker can facilitate account takeover of any user, including the host. The issue was addressed in version 0.25.3 by adding missing authorization checks.
Affected products
- usememos memos 0.25.2
Timeline
- 2025-11-03: other: First contact with vendor
- 2025-11-04: other: Pull request submitted
- 2025-11-06: patched: Fix merged to main branch
- 2025-11-25: other: Version 0.25.3 released
- 2025-12-03: advisory: Researcher advisory published by usd HeroLab
- 2025-12-08: disclosed: CVE published to NVD