| id: GO-2025-4218 |
| modules: |
| - module: github.com/usememos/memos |
| versions: |
| - fixed: 0.25.3 |
| vulnerable_at: 0.25.2 |
| summary: memos lacks file name validation or verification in github.com/usememos/memos |
| cves: |
| - CVE-2025-65799 |
| ghsas: |
| - GHSA-qgjp-5g5x-vhq2 |
| references: |
| - advisory: https://github.com/advisories/GHSA-qgjp-5g5x-vhq2 |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-65799 |
| - fix: https://github.com/usememos/memos/commit/5f57f48673e2054f404b2c5b497a8eaa3690591d |
| - fix: https://github.com/usememos/memos/pull/5218 |
| - web: http://memos.com |
| - web: http://usememos.com |
| - web: https://herolab.usd.de/security-advisories/usd-2025-0056 |
| source: |
| id: GHSA-qgjp-5g5x-vhq2 |
| created: 2025-12-15T12:56:29.682525309-05:00 |
| review_status: UNREVIEWED |