usememos Memos Identity Provider Service Access Control Vulnerability

Vulnerability

A broken access control vulnerability has been identified in the Identity Provider service of usememos Memos version 0.25.2. This vulnerability allows low-privileged users to arbitrarily modify or delete registered identity providers. The issue arises from missing authorization checks, which can lead to account takeover or a denial-of-service condition by disrupting the identity provider management process.

Impact

Exploitation of this vulnerability could result in unauthorized modifications or deletions of identity providers, causing account takeovers or denial-of-service conditions.

Reproduction

Low-privileged users can delete identity providers, causing a denial-of-service by disrupting the sign-in process. Additionally, they can modify identity provider configurations, including sensitive information like client secrets, which can be exploited to impersonate the Memos instance at the identity provider.

Remediation

Users can update to Memos version 0.25.3, which addresses this vulnerability by adding the necessary authorization checks. Instructions for updating are available in the Memos documentation.

Added: Dec 8, 2025, 5:19 PM
Updated: Dec 8, 2025, 10:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.6
remediation
7.7
relevance
1.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.