CVE-2025-22952: SSRF
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22952?
CVE-2025-22952 is classified as a high severity vulnerability due to its potential for exploitation through Server-Side Request Forgery (SSRF) attacks.
How do I fix CVE-2025-22952?
To fix CVE-2025-22952, ensure proper validation of user-supplied URLs to prevent SSRF vulnerabilities, ideally by using a safe URL parsing library.
Which versions of Memos are affected by CVE-2025-22952?
CVE-2025-22952 affects Memos versions up to and including 0.24.0.
What type of vulnerability is CVE-2025-22952?
CVE-2025-22952 is a Server-Side Request Forgery (SSRF) vulnerability caused by insufficient validation of URLs.
Can CVE-2025-22952 lead to data breaches?
Yes, exploitation of CVE-2025-22952 can lead to unauthorized access to sensitive data within the network.