Medium severity4.3NVD Advisory· Published Oct 11, 2026
CVE-2026-108727
CVE-2026-108727
Description
EdgeEver through 1.108.0 contains a missing authorization vulnerability in the Hono API memo-template routes that allows holders of scoped API tokens to bypass token scope restrictions because template handlers never call requireScopes. Attackers with a token lacking write:memos can save a template and invoke POST /api/v1/templates/:id/use to create memos, and list, modify, or delete templates in the token owner's workspace.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/tianma-if/edgeever/blob/0ef9a1df9c849a64047aba64c70331c2badf8b39/apps/api/src/memo-routes.tsnvd
- github.com/tianma-if/edgeever/blob/0ef9a1df9c849a64047aba64c70331c2badf8b39/apps/api/src/template-routes.tsnvd
- hackmd.io/@haind/edgeever-template-write-memos-scope-bypassnvd
- www.vulncheck.com/advisories/edgeever-through-1.108.0-missing-authorization-via-memo-template-api-routesnvd
News mentions
0No linked articles in our index yet.