Impact
This flaw exists in EdgeEver’s Hono API memo‑template routes, where template handlers do not enforce required scopes. As a result, holders of any scoped API token can bypass the intended write:memos restriction. Attackers with a token that lacks this scope can save a template, invoke the route to use that template, and thereby create memos, as well as list, modify, or delete templates owned by the token’s original workspace. The vulnerability effectively grants unauthorized access and control within a user’s workspace, enabling data manipulation and potential further exploitation.
Affected Systems
EdgeEver, developed by Tianma IF, is affected in all releases up to and including version 1.108.0. The issue resides in the memo‑template API endpoints, exposing the token‑owner’s workspace to any token that does not have write scopes. Admins should locate installations running 1.108.0 or older and treat them as vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, and no EPSS score is available, so the exact exploitation probability is unclear. The vulnerability is not yet listed in the CISA KEV catalog. Because it is a missing authorization flaw (CWE‑862), once discovered, an attacker can perform privileged operations inside the workspace by simply using a legitimate API call set to a token lacking the proper scope. The attack vector therefore relies on authentic API traffic and existing tokens, making it potentially easy to exploit once the flaw is known.
OpenCVE Enrichment