CVE-2025-22952
CRITICAL EXPLOITED NUCLEIMemos - SSRF
Title source: ruleDescription
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.
Nuclei Templates (1)
Elestio Memos <= v0.24.0 - Server-Side Request Forgery
CRITICALVERIFIEDby iamnoooob,rootxharsh,pdresearch
Shodan:
http.favicon.hash:-1924700661
Scores
CVSS v3
9.8
EPSS
0.2493
EPSS Percentile
96.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2026-04-12
CWE
CWE-918
Status
published
Products (2)
usememos/memos
0.23.0
usememos/memos
0Go
Published
Feb 27, 2025
Tracked Since
Feb 18, 2026