VDB
Sign up
MEDIUM6.1

GHSA-9w8x-5hv5-r6gw

Cross Site Scripting in usememos/memos

Quick fix

GHSA-9w8x-5hv5-r6gw — github.com/usememos/memos: upgrade to the fixed version with the command below.

go get github.com/usememos/memos@v0.10.4-0.20230211093429-b11d2130a084

Details

All versions of the package github.com/usememos/memos/server prior to 0.11.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/usememos/memos
Introduced in: 0Fixed in: 0.10.4-0.20230211093429-b11d2130a084
Fixgo get github.com/usememos/memos@v0.10.4-0.20230211093429-b11d2130a084

References