Record summary

CVE-2024-29028 has a selected CVSS score of 5.8 (medium); EIP currently links 1 Nuclei template.

Description

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vulnerability is fixed in 0.16.1.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 26, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 25, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unknown

CVE List, VulnCheckBefore 0.13.2affected
< 0.16.1affected

github.com/usememos/memos

Browse Go / github.com/usememos/memos
GitHub AdvisoryBefore 0.16.1 · Fixed in 0.16.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMMemos 0.13.2 - Server-Side Request ForgeryCVSS 5.3

SSRF vulnerabilities exist in the memos API service `/o/get/httpmeta` that allow unauthenticated and authenticated users to enumerate and read from the internal network. In addition, one SSRF vulnerability leads to a reflected XSS vulnerability, which may allow an attacker complete control over the administrator account.

Impact

Attackers can make the server perform requests to arbitrary internal or external resources, potentially accessing sensitive data or internal services.

Remediation

Update Memos to version 0.13.3 or later.

WeaknessesCWE-918
Authorsritikchaddha
Template tagscvecve2024ssrfmemosvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Shodan: title:"Memos"
FOFA: title="Memos"

Source: ProjectDiscovery

References

4