elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.
References
Link | Resource |
---|---|
https://elest.io/open-source/memos | Product |
https://github.com/usememos/memos | Product |
https://github.com/usememos/memos/issues/4413 | Exploit Issue Tracking Vendor Advisory |
https://github.com/usememos/memos/pull/4428 | Issue Tracking Patch |
https://github.com/usememos/memos/issues/4413 | Exploit Issue Tracking Vendor Advisory |
Configurations
History
10 Jul 2025, 22:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://elest.io/open-source/memos - Product | |
References | () https://github.com/usememos/memos - Product | |
References | () https://github.com/usememos/memos/issues/4413 - Exploit, Issue Tracking, Vendor Advisory | |
References | () https://github.com/usememos/memos/pull/4428 - Issue Tracking, Patch | |
CPE | cpe:2.3:a:usememos:memos:0.23.0:-:*:*:*:*:*:* | |
First Time |
Usememos
Usememos memos |
03 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/usememos/memos/issues/4413 - | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
Summary |
|
|
CWE | CWE-918 |
27 Feb 2025, 20:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-27 20:16
Updated : 2025-07-10 22:52
NVD link : CVE-2025-22952
Mitre link : CVE-2025-22952
CVE.ORG link : CVE-2025-22952
JSON object : View
Products Affected
usememos
- memos
CWE
CWE-918
Server-Side Request Forgery (SSRF)