CVE-2025-22952
CRITICAL EXPLOITED NUCLEIMemos 0.23.0 URL Validation - Server-Side Request Forgery
Title source: manualExploitation Summary
CVE-2025-22952 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.
Description
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.
Nuclei Templates (1)
Elestio Memos <= v0.24.0 - Server-Side Request Forgery
CRITICALVERIFIEDby iamnoooob,rootxharsh,pdresearch
Shodan:
http.favicon.hash:-1924700661
References (4)
Core 4
Core References
Exploit, Issue Tracking, Vendor Advisory
https://github.com/usememos/memos/issues/4413
Issue Tracking, Patch
https://github.com/usememos/memos/pull/4428
Scores
CVSS v3
9.8
EPSS
0.0282
EPSS Percentile
84.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
VulnCheck KEV
2026-04-12
CWE
CWE-918
Status
published
Products (2)
usememos/memos
0.23.0
usememos/memos
0Go
Published
Feb 27, 2025
Tracked Since
Feb 18, 2026