Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the digest itself, contains a cross-site scripting (XSS) vulnerability in both topic names and channel names. This issue has been fixed in Zulip Server 10.4. A workaround for this issue involves denying access to /digest/.
Metrics
Affected Vendors & Products
References
History
Thu, 02 Oct 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zulip zulip Server
|
|
| CPEs | cpe:2.3:a:zulip:zulip:2.0.0:rc1:*:*:*:*:*:* |
cpe:2.3:a:zulip:zulip_server:*:*:*:*:*:*:*:* cpe:2.3:a:zulip:zulip_server:2.0.0:rc1:*:*:*:*:*:* |
| Vendors & Products |
Zulip zulip Server
|
Wed, 27 Aug 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:zulip:zulip:*:*:*:*:*:*:*:* cpe:2.3:a:zulip:zulip:2.0.0:rc1:*:*:*:*:*:* |
Wed, 02 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Jul 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the digest itself, contains a cross-site scripting (XSS) vulnerability in both topic names and channel names. This issue has been fixed in Zulip Server 10.4. A workaround for this issue involves denying access to /digest/. | |
| Title | Zulip XSS in digest preview URL | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-02T19:31:12.064Z
Updated: 2025-07-02T19:37:15.550Z
Reserved: 2025-06-18T03:55:52.035Z
Link: CVE-2025-52559
Updated: 2025-07-02T19:37:04.875Z
Status : Analyzed
Published: 2025-07-02T20:15:31.443
Modified: 2025-10-02T01:51:09.033
Link: CVE-2025-52559
No data.