CVE-2025-56760
When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint co
When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server.
MEDIUM · CVSS 4.3
EPSS 0.00178
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0