Memos Access Token Vulnerability (CVE-2024-21635) — High Severity

Unsecured Access: Memos Access Token Vulnerability (CVE-2024-21635)

Imagine changing the locks on your house, but an intruder who already had a copy of the old key can still walk right in. This is similar to a significant security flaw recently identified in Memos, a popular lightweight note-taking service. This vulnerability, tracked as CVE-2024-21635, means that if your Memos account is ever compromised, simply changing your password might not be enough to kick out the unauthorized user.

Specifically, when a user updates their password in Memos, any existing “Access Tokens” linked to their account remain active. These tokens act like digital keys that allow applications to access your Memos account without needing your password each time. An attacker who obtained one of these tokens before you changed your password could continue to access your notes and data, even after you’ve secured your account with a new password. To fully secure your account, you would have to manually find and delete the specific unauthorized access token, which is made difficult by generic descriptions that don’t clearly identify which token belongs to whom.

CVE Details

  • Product: Memos
  • Published: November 14, 2025
  • Severity: High (CVSS Score 7.5)
  • Status: Analyzed

Affected Products

The vulnerability impacts Memos versions up to and including 0.18.1. Users running these versions are at risk if their accounts are compromised.

Current Status

This vulnerability has been analyzed and publicly disclosed. While the initial vulnerability data indicated no patched version was available, further research shows that a fix has been released.

Severity Level

This vulnerability is rated as High severity, with a CVSS Score of 7.5. The risk stems from the fact that an attacker could maintain persistent access to a user’s account even after a password reset, leading to potential ongoing data exposure or modification without the user’s immediate knowledge or ability to stop it through a simple password change.

Possible Solutions

The good news is that a patched version, Memos v0.18.2, is available to address this issue. It is crucial for all users running affected versions to upgrade to Memos v0.18.2 or later as soon as possible. This update is designed to automatically revoke all existing Access Tokens when a password change occurs, effectively logging out all active sessions and requiring users to re-authenticate.

If you suspect your account might have been compromised before upgrading, it’s a good practice to log into your Memos account after updating to v0.18.2, navigate to your Access Token settings, and manually delete any unfamiliar or suspicious tokens. Additionally, enabling multi-factor authentication (if available in your Memos setup or via a third-party authenticator) can significantly enhance your account security against unauthorized access.

References

https://github.com/usememos/memos/security/advisories/GHSA-mr34-8733-grr2
https://github.com/usememos/memos/security/advisories/GHSA-mr34-8733-grr2

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.