CVE-2025-50738

The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or interaction beyond viewing the memo. This can be exploited by an attacker to disclose the viewing user's IP address, browser User-Agent string, and potentially other request-specific information to the attacker-controlled server, leading to information disclosure and user tracking.
Configurations

No configuration.

History

29 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-29 15:15

Updated : 2025-07-29 15:15


NVD link : CVE-2025-50738

Mitre link : CVE-2025-50738

CVE.ORG link : CVE-2025-50738


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor