GHSA-hfcf-79gh-f3jc

Suggest an improvement
Source
https://github.com/advisories/GHSA-hfcf-79gh-f3jc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-hfcf-79gh-f3jc/GHSA-hfcf-79gh-f3jc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hfcf-79gh-f3jc
Aliases
  • CVE-2025-50738
Published
2025-07-29T15:31:50Z
Modified
2025-07-29T22:59:51.558218Z
Severity
  • 5.2 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:P CVSS Calculator
Summary
Memos has Cross-Site Scripting (XSS) Vulnerability in Image URLs
Details

The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or interaction beyond viewing the memo. This can be exploited by an attacker to disclose the viewing user's IP address, browser User-Agent string, and potentially other request-specific information to the attacker-controlled server, leading to information disclosure and user tracking.

Database specific
{
    "github_reviewed": true,
    "nvd_published_at": "2025-07-29T15:15:35Z",
    "github_reviewed_at": "2025-07-29T22:09:45Z",
    "severity": "MODERATE",
    "cwe_ids": [
        "CWE-200",
        "CWE-79"
    ]
}
References

Affected packages

Go / github.com/usememos/memos

Package

Name
github.com/usememos/memos
View open source insights on deps.dev
Purl
pkg:golang/github.com/usememos/memos

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.24.4