CVE-2025-22952: Usememos Memos

Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.

elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.

Affected products

Published 2025-02-27. Last modified 2026-06-17.