CVE-2025-65795: n/a
Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.
AI Analysis
Technical Summary
CVE-2025-65795 describes an access control weakness in usememos memos v0.25.2 at the /api/v1/user endpoint. Due to improper authorization checks, attackers without privileges can create arbitrary accounts by crafting specific requests to this API endpoint. This vulnerability is categorized under CWE-284 (Improper Access Control). The CVSS 3.1 vector indicates the attack can be performed remotely without privileges or user interaction, impacting integrity but not confidentiality or availability.
Potential Impact
Exploitation of this vulnerability allows an attacker to create arbitrary user accounts without authorization. This can lead to unauthorized access or manipulation of the system's user base, potentially undermining application integrity. There is no indication of direct confidentiality or availability impact. No known exploits are reported in the wild at this time.
Mitigation Recommendations
No patch or official fix is currently available for this vulnerability. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, restrict access to the affected endpoint where possible and monitor for suspicious account creation activity.
CVE-2025-65795: n/a
Description
Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-65795 describes an access control weakness in usememos memos v0.25.2 at the /api/v1/user endpoint. Due to improper authorization checks, attackers without privileges can create arbitrary accounts by crafting specific requests to this API endpoint. This vulnerability is categorized under CWE-284 (Improper Access Control). The CVSS 3.1 vector indicates the attack can be performed remotely without privileges or user interaction, impacting integrity but not confidentiality or availability.
Potential Impact
Exploitation of this vulnerability allows an attacker to create arbitrary user accounts without authorization. This can lead to unauthorized access or manipulation of the system's user base, potentially undermining application integrity. There is no indication of direct confidentiality or availability impact. No known exploits are reported in the wild at this time.
Mitigation Recommendations
No patch or official fix is currently available for this vulnerability. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, restrict access to the affected endpoint where possible and monitor for suspicious account creation activity.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2025-11-18T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 6936fa8b3bff8e510987a73d
Added to database: 12/08/2025, 16:19:23 UTC
Last enriched: 07/05/2026, 21:06:38 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 219
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.