Impact
Memos v0.30.0 and earlier omit the 100.64.0.0/10 carrier-grade NAT range from its SSRF mitigation, allowing unauthenticated callers to request internal resources. This is a Server Side Request Forgery (CWE-918) weakness. An attacker can submit a link that causes the server to fetch a page within that private range; the server then returns the page title and description, exposing internal host information and potentially cloud metadata service data.
Affected Systems
Memos versions 0.30.0 and earlier, released by usememos/memos.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. This is a Server Side Request Forgery (CWE-918) vulnerability. Exploitation requires sending a crafted link to the link‑metadata endpoint and is feasible over the public interface, so unauthenticated attackers can bypass IP validation and reach internal hosts in the omitted range. No exploit probability data is available and the vulnerability is not listed in CISA KEV. Attackers can read limited information such as page titles and descriptions, which may assist in further attacks, but the direct impact is information disclosure and potential pivot to internal services.
OpenCVE Enrichment