VulnSea

MemOS vulnerabilities

CVEs whose affected-version data names the MemOS package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-75110Critical· 9.8PoC
1mo ago

MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET

MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset, the is_internal_reques…

AbyssalMemTensor · MemOSEPSS 0.52%via CVEORG
CVE-2025-65799Medium· 4.3
9mo ago

A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.

A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.

Sunlitusememos · memosEPSS 0.21%via NVD
CVE-2025-65797Medium· 6.5
9mo ago

Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Ser…

Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Ser…

Sunlitusememos · memosEPSS 0.28%via NVD
CVE-2025-65795High· 7.5
9mo ago

Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.

Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.

Twilightusememos · memosEPSS 0.26%via NVD
CVE-2025-65798Medium· 5.4
9mo ago

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.

Sunlitusememos · memosEPSS 0.18%via NVD
CVE-2025-65796Medium· 4.3
9mo ago

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.

Sunlitusememos · memosEPSS 0.20%via NVD
MemOS vulnerabilities (CVEs) · VulnSea