Executive brief
A vulnerability in the Memos note-taking application allows users with low-level account access to modify or delete file attachments belonging to other users. This could lead to the unauthorized deletion of data from the server or the exposure of private attachments by making them public. The issue affects organizations or individuals using the self-hosted platform for private knowledge management and daily logging.
Technical details
A broken access control vulnerability (CWE-862) exists in the Memo Attachment service of usememos memos v0.25.2. The application fails to validate the ownership of a memo or its associated attachments when processing update requests via the gRPC-Gateway REST API. An authenticated attacker can send a crafted PATCH request to the `/api/v1/memos/{memo_id}/attachments` endpoint to reassign arbitrary attachment IDs to their own memos or remove them entirely. Unassigning an attachment triggers its deletion from the server's disk, while reassigning a private attachment to a public memo makes the file accessible to others. The vulnerability was addressed in version 0.25.3 by adding proper authorization checks to the attachment and relation services.
Affected products
- usememos memos 0.25.2
Timeline
- 2025-11-03: disclosed: First contact with vendor
- 2025-11-04: other: Pull request submitted
- 2025-11-06: patched: Fix merged to main branch
- 2025-11-25: other: Version 0.25.3 released
- 2025-12-03: advisory: Security advisory published by usd HeroLab