VDB
GO-2025-3492
GO-2025-3492
PUBLISHED
CVSS 8.699999809265137 HIGH
Memos Server-Side Request Forgery (SSRF) in github.com/usememos/memos
Risk Scores
CVSS v4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:L/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | usememos/memos | 0, 0 |
Timeline
- Mar 3, 2025 CVE Published
- Mar 3, 2026 CVE Updated
- May 1, 2026 Security Advisory
References
- https://github.com/advisories/GHSA-wfxg-v3j4-7qmj advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-22952 advisory
- https://github.com/usememos/memos/commit/f17774cb3b9612495d89576a91ab3480018cb0b6 patch
- https://github.com/usememos/memos/commit/f8c973c938742827baaf6665cfe66805dc8e8d02 patch
- https://github.com/usememos/memos/pull/4421 patch
- https://github.com/usememos/memos/pull/4428 patch
- https://github.com/usememos/memos/issues/4413 report
- https://elest.io/open-source/memos url