Executive brief
A security vulnerability exists in Memos, a self-hosted note-taking application, specifically within its file attachment service. An authenticated user could exploit this flaw to save files outside of the intended storage directory, potentially overwriting critical system or application files. In practice, this could allow an attacker to corrupt the application's database, leading to data loss or service disruption.
Technical details
A path traversal vulnerability (CWE-23/CWE-73) exists in the Attachment service of usememos memos v0.25.2. The application fails to validate or sanitize filenames provided during attachment creation or updates when local storage is used. An authenticated, low-privileged attacker can supply a filename containing traversal sequences (e.g., '../../') to write files to arbitrary locations on the host filesystem. This can be leveraged to overwrite the SQLite database file (memos_prod.db), resulting in data corruption or a denial-of-service condition. The issue was addressed in version 0.25.3 by implementing a 'validateFilename' function that rejects directory separators and dangerous path patterns.
Affected products
- usememos memos 0.25.2
Timeline
- 2025-11-03: disclosed: First contact and pull request submitted
- 2025-11-05: patched: Fix merged to main branch
- 2025-11-25: patched: Version 0.25.3 released
- 2025-12-03: advisory: Third-party advisory published by usd HeroLab
- 2025-12-08: advisory: NVD publication date