Critical severity9.8NVD Advisory· Published Jul 29, 2025· Updated Jun 17, 2026
CVE-2025-50738
CVE-2025-50738
Description
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or interaction beyond viewing the memo. This can be exploited by an attacker to disclose the viewing user's IP address, browser User-Agent string, and potentially other request-specific information to the attacker-controlled server, leading to information disclosure and user tracking.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/usememos/memosGo | < 0.24.4 | 0.24.4 |
Affected products
6- ghsa-coords4 versionspkg:golang/github.com/usememos/memospkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Tumbleweedpkg:rpm/suse/govulncheck-vulndb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6
< 0.24.4+ 3 more
- (no CPE)range: < 0.24.4
- (no CPE)range: < 0.0.20250811T192933-1.1
- (no CPE)range: < 0.0.20250814T182633-150000.1.98.1
- (no CPE)range: < 0.0.20250814T182633-150000.1.98.1
- Memos application/Memos applicationdescription
Patches
Vulnerability mechanics
References
5- github.com/usememos/memos/issues/4707nvdExploitIssue TrackingWEB
- github.com/advisories/GHSA-hfcf-79gh-f3jcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-50738ghsaADVISORY
- github.com/fai1424/Vulnerability-Research/tree/main/CVE-2025-50738nvdWEB
- github.com/usememos/memos/commit/46d5307d7f210067b46e07400a728fa9095803d9ghsaWEB
News mentions
0No linked articles in our index yet.