Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-50738 PoC — Memos 安全漏洞

Source
Associated Vulnerability
Title:Memos 安全漏洞 (CVE-2025-50738)
Description:Memos是Memos开源的一个具有知识管理和社交功能的开源自托管备忘录中心。 Memos v0.24.3及之前版本存在安全漏洞,该漏洞源于允许嵌入任意URL的markdown图像,可能导致信息泄露。
Description
An authenticated attacker can upload a specially crafted SVG file containing JavaScript code to Memos versions prior to 0.25.0, leading to a stored cross-site scripting (XSS) vulnerability.
File Snapshot

id: CVE-2025-50738 info: name: Memos < 0.25.0 - Stored Cross-Site Scripting author: SeongHyeonJ ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.