Unsecured Access: Memos Access Token Vulnerability (CVE-2024-21635)
Imagine changing the locks on your house, but an intruder who already had a copy of the old key can still walk right in. This is similar to a significant security flaw recently identified in Memos, a popular lightweight note-taking service. This vulnerability, tracked as CVE-2024-21635, means that if your Memos account is ever compromised, simply changing your password might not be enough to kick out the unauthorized user.
Specifically, when a user updates their password in Memos, any existing “Access Tokens” linked to their account remain active. These tokens act like digital keys that allow applications to access your Memos account without needing your password each time. An attacker who obtained one of these tokens before you changed your password could continue to access your notes and data, even after you’ve secured your account with a new password. To fully secure your account, you would have to manually find and delete the specific unauthorized access token, which is made difficult by generic descriptions that don’t clearly identify which token belongs to whom.
CVE Details
- Product: Memos
- Published: November 14, 2025
- Severity: High (CVSS Score 7.5)
- Status: Analyzed
Affected Products
The vulnerability impacts Memos versions up to and including 0.18.1. Users running these versions are at risk if their accounts are compromised.
Current Status
This vulnerability has been analyzed and publicly disclosed. While the initial vulnerability data indicated no patched version was available, further research shows that a fix has been released.
Severity Level
This vulnerability is rated as High severity, with a CVSS Score of 7.5. The risk stems from the fact that an attacker could maintain persistent access to a user’s account even after a password reset, leading to potential ongoing data exposure or modification without the user’s immediate knowledge or ability to stop it through a simple password change.
Possible Solutions
The good news is that a patched version, Memos v0.18.2, is available to address this issue. It is crucial for all users running affected versions to upgrade to Memos v0.18.2 or later as soon as possible. This update is designed to automatically revoke all existing Access Tokens when a password change occurs, effectively logging out all active sessions and requiring users to re-authenticate.
If you suspect your account might have been compromised before upgrading, it’s a good practice to log into your Memos account after updating to v0.18.2, navigate to your Access Token settings, and manually delete any unfamiliar or suspicious tokens. Additionally, enabling multi-factor authentication (if available in your Memos setup or via a third-party authenticator) can significantly enhance your account security against unauthorized access.
References
https://github.com/usememos/memos/security/advisories/GHSA-mr34-8733-grr2
https://github.com/usememos/memos/security/advisories/GHSA-mr34-8733-grr2



