GHSA-47v8-26mf-hw38HighCVSS 8.1

Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their...

Published
September 1, 2026
Last Modified
September 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens and rotate the refresh token indefinitely, bypassing the password change security measure.

🔗 References (6)