In usememos/memos 0.9.0 and prior, a user can view any content from private memos from other users via the API. References https://nvd.nist.gov/vuln/detail/CVE-2022-4810 https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53 https://huntr.dev/bounties/f0c8d778-db86-4ed3-85bb-5315ab56915e https://github.com/advisories/GHSA-qf9q-3wwx-8qjv