Loading HuntDB...

GHSA-j2gj-g3p9-7mrr

GitHub Security Advisory

Account TakeOver Due to Improper Handling of JWT Tokens in usememos/memos

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

Improper Access Control in GitHub repository usememos/memos prior to 0.13.2. As of commit `c9aa2eeb9` access tokens which fail validation are rejected.

Affected Packages

Go github.com/usememos/memos
Affected versions: 0 (fixed in 0.13.2)

Related CVEs

Key Information

GHSA ID
GHSA-j2gj-g3p9-7mrr
Published
September 1, 2023 3:30 AM
Last Modified
September 1, 2023 9:43 PM
CVSS Score
9.0 /10
Primary Ecosystem
Go
Primary Package
github.com/usememos/memos
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.