Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the digest itself, contains a cross-site scripting (XSS) vulnerability in both topic names and channel names. This issue has been fixed in Zulip Server 10.4. A workaround for this issue involves denying access to /digest/.
Metrics
Affected Vendors & Products
References
History
Wed, 27 Aug 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:zulip:zulip:*:*:*:*:*:*:*:* cpe:2.3:a:zulip:zulip:2.0.0:rc1:*:*:*:*:*:* |
Wed, 02 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Jul 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the digest itself, contains a cross-site scripting (XSS) vulnerability in both topic names and channel names. This issue has been fixed in Zulip Server 10.4. A workaround for this issue involves denying access to /digest/. | |
| Title | Zulip XSS in digest preview URL | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-02T19:31:12.064Z
Updated: 2025-07-02T19:37:15.550Z
Reserved: 2025-06-18T03:55:52.035Z
Link: CVE-2025-52559
Updated: 2025-07-02T19:37:04.875Z
Status : Analyzed
Published: 2025-07-02T20:15:31.443
Modified: 2025-08-27T13:37:33.070
Link: CVE-2025-52559
No data.