An authenticated attacker can upload a specially crafted SVG file containing JavaScript code to Memos versions prior to 0.25.0, leading to a stored cross-site scripting (XSS) vulnerability.
id: CVE-2025-50738
info:
name: Memos < 0.25.0 - Stored Cross-Site Scripting
author: SeongHyeonJ
...