memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the response of the current server request, causing a reflected XSS vulnerability. Version 0.22.0 of memos removes the vulnerable file.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2024-2545 | memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the response of the current server request, causing a reflected XSS vulnerability. Version 0.22.0 of memos removes the vulnerable file. |
![]() |
GHSA-9cqm-mgv9-vv9j | memos vulnerable to Server-Side Request Forgery and Cross-site Scripting |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 02 Jan 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Usememos
Usememos memos |
|
CPEs | cpe:2.3:a:usememos:memos:*:*:*:*:*:*:*:* | |
Vendors & Products |
Usememos
Usememos memos |

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T01:03:51.649Z
Reserved: 2024-03-14T16:59:47.612Z
Link: CVE-2024-29029

Updated: 2024-04-19T18:10:36.654Z

Status : Analyzed
Published: 2024-04-19T16:15:09.853
Modified: 2025-01-02T20:46:24.867
Link: CVE-2024-29029

No data.

No data.