An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by sett…
High CVSS 8.5
Summary
An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://gist.github.com/seiyaibuki0523/d8af15eb555808319a2633269a9ebb80
- https://github.com/usememos/memos
- https://gist.github.com/seiyaibuki0523/d8af15eb555808319a2633269a9ebb80
Timeline
- nvd_ingest NVD