CVE-2025-50738: Infoleak
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or interaction beyond viewing the memo. This can be exploited by an attacker to disclose the viewing user's IP address, browser User-Agent string, and potentially other request-specific information to the attacker-controlled server, leading to information disclosure and user tracking.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50738?
CVE-2025-50738 is considered a medium severity vulnerability due to the potential for arbitrary image URLs to be fetched without user consent.
How do I fix CVE-2025-50738?
To fix CVE-2025-50738, update the Memos application to a version later than v0.24.3 that addresses this vulnerability.
What are the risks associated with CVE-2025-50738?
The risks associated with CVE-2025-50738 include unauthorized data exposure and potential abuse by malicious actors embedding harmful content.
Who is affected by CVE-2025-50738?
CVE-2025-50738 affects all users of the Memos application up to version v0.24.3.
Can CVE-2025-50738 lead to other security issues?
Yes, CVE-2025-50738 can lead to other security issues such as drive-by downloads or cross-site scripting if exploited.