A AegiFlow
LOWCVSS 2.1EPSS 0.3%

CVE-2026-6634

Memos has an Incorrect Privilege Assignment issue

Published
2026-04-20
Modified
2026-07-21
EPSS percentile
17%
Aliases
GHSA-gqp3-hfc3-8q54
Sources
github-advisory

Summary

A weakness has been identified in usememos memos up to 0.22.1. This affects the function memos_access_token of the file src/App.tsx of the component UpdateInstanceSetting. This manipulation of the argument additionalStyle/additionalScript causes improper authorization. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/usememos/memos

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.