CVE-2025-50738 — Stored XSS via SVG

About

One night, I got bored and decided to deploy some FOSS projects. I came across a project called usememos — a program that lets you take notes in a Twitter-style environment, which I think is a pretty unique idea!

Write-up

It is quite simple, a stored XSS via SVG is a very common way of finding Cross-Site Scripting in the wild, so it was one of the first things I did.

I deployed the usememos via Pikapods, where I then navigated to the front-page and created an account.
With the account, I created a ’thought':

Which I then created an SVG file, containing the following payload:

<?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">

<svg version="1.1" baseProfile="full" xmlns="http://www.w3.org/2000/svg" onload="alert(document.domain)">
   <polygon id="triangle" points="0,0 0,50 50,0" fill="#009900" stroke="#004400"/>
</svg>

This payload executes JavaScript, resulting in printing the ‘document.domain’ (so it just shows ‘*.pikapod.net’).

I selected the file, in this case it was called xss6.svg and I could then ‘copy image address’:

As you notice, the XSS does not execute inside the main page, sadly. I tried some maneuvers to get it to work, but without success.

So entering the copied URL, results in a XSS pop-up – revealing the URL:

Reporting the vulnerability

The impact of the vulnerability is not that high, but it does possibly allow for stealing cookies and forging requests, the default XSS risks.

First, I created an issue in the Security tab of GitHub of the ‘usememos’ repository. But after some time waiting, I looked at how others have reported it, and this was via the issues page. This is where I created this issue ‘https://github.com/usememos/memos/issues/4707’.

As seen in the issue, ‘boojack’ (developer) fixed the issue right away.

Now the waiting can begin

I went to https://cveform.mitre.org and filled in all the forms.
Now, when I submitted it, it was 21 May 2025.

I waited for 2,5 months – where I was met with a message indicating that my vulnerability was a ‘duplicate’.
This is not correct, so looking at the vulnerability at Snyk I did get the credits – and of course, the issue is mentioned.

All this resulted in finally having a CVE, after not even putting that much effort into it, just out of boredom and a little experimenting with new software.

The CVSS score

Well.. here comes the fun part.
Let’s take a look at what CVSS it has when looking at the Nessus summary of it: https://www.tenable.com/cve/CVE-2025-50738

For CVSSv3, it has a 9.8 Critical – this can’t be right.

Also at NIST it shows the following: ‘https://nvd.nist.gov/vuln/detail/CVE-2025-50738’:

And for the ENISA from Europe, we also find it being Critical: ‘https://euvd.enisa.europa.eu/vulnerability/CVE-2025-50738’

I have no idea what has gone wrong with calculating this stored XSS, but I’ll take a critical (this is for sure not a critical, and should be a medium at most).