CVE-2025-65797: Usememos Memos
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS).
Affected products
- Usememos Memos: version 0.25.2 only
Published 2025-12-08. Last modified 2026-07-05.