FlawAtlas
Search the atlas
CVE-2025-56760 Moderate

Memos Vulnerable to Path Traversal via the CreateResource Endpoint in github.com/usememos/memos

Memos Vulnerable to Path Traversal via the CreateResource Endpoint in github.com/usememos/memos

Exploit probability 0.3%
Published September 8, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

2 explicit affected versions

Go github.com/usememos/memos
Go github.com/usememos/memos

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-56760

When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server.

View original source
Open Source Vulnerabilities GO-2025-3936

Memos Vulnerable to Path Traversal via the CreateResource Endpoint in github.com/usememos/memos

View original source
Open Source Vulnerabilities GHSA-78j5-8vq7-jxv5

When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server.

View original source

05 / REFERENCES

Further evidence