PT-2026-70208 · Usememos · Usememos
CVE-2026-51583
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
usememos versions prior to 0.31.0
Description
A remote authenticated attacker can perform Server-Side Request Forgery (SSRF) by exploiting the Webhook validation mechanism located in
internal/webhook/validate.go. This occurs when a webhook target is set to an internal address, allowing the attacker to induce the server to make requests to internal resources.Recommendations
Update usememos to version 0.31.0 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Usememos