← volver
CVE-2026-6634

usememos UpdateInstanceSetting App.tsx memos_access_token improper authorization

CVSS 5.3 MEDIUMEPSS 0.3%CWE-266CWE-285
Vexday Risk Score
33Atención
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS 5.3EPSS 0.3%KEV nãoPoC públicaNuclei Metasploit Patch
Ciclo de vida
20 abr 2026Publicada en NVD
Recomendación: Planificar corrección próxima — ya existe PoC pública.
A weakness has been identified in usememos memos up to 0.22.1. This affects the function memos_access_token of the file src/App.tsx of the component UpdateInstanceSetting. This manipulation of the argument additionalStyle/additionalScript causes improper authorization. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
usememos · memos
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →