GHSA-qmhr-x227-7hgfHighCVSS 8.5

An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server...

Published
August 11, 2026
Last Modified
August 12, 2026

🔗 CVE IDs covered (1)

📋 Description

An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address.

🔗 References (4)