Vulnerability Description
When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Usememos | Memos | 0.22.0 |
Related Weaknesses (CWE)
References
- https://github.com/usememos/memos/blob/v0.24.4/server/router/api/v1/resource_serProduct
- https://www.sonarsource.com/blog/securing-go-applications-with-sonarqube-real-woExploitPatchThird Party Advisory
FAQ
What is CVE-2025-56760?
CVE-2025-56760 is a vulnerability with a CVSS score of 4.3 (MEDIUM). When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on...
How severe is CVE-2025-56760?
CVE-2025-56760 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-56760?
Check the references section above for vendor advisories and patch information. Affected products include: Usememos Memos.