blob: ab38c3cee98afe5cb339200fefac2626aac9e18a [file] [log] [blame]
id: GO-2025-3492
modules:
- module: github.com/usememos/memos
unsupported_versions:
- last_affected: 0.24.0
vulnerable_at: 0.24.0
summary: Memos Server-Side Request Forgery (SSRF) in github.com/usememos/memos
cves:
- CVE-2025-22952
ghsas:
- GHSA-wfxg-v3j4-7qmj
references:
- advisory: https://github.com/advisories/GHSA-wfxg-v3j4-7qmj
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-22952
- fix: https://github.com/usememos/memos/commit/f17774cb3b9612495d89576a91ab3480018cb0b6
- fix: https://github.com/usememos/memos/commit/f8c973c938742827baaf6665cfe66805dc8e8d02
- fix: https://github.com/usememos/memos/pull/4421
- fix: https://github.com/usememos/memos/pull/4428
- report: https://github.com/usememos/memos/issues/4413
- web: https://elest.io/open-source/memos
source:
id: GHSA-wfxg-v3j4-7qmj
created: 2025-03-03T11:25:38.023363-05:00
review_status: UNREVIEWED