Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the digest itself, contains a cross-site scripting (XSS) vulnerability in both topic names and channel names. This issue has been fixed in Zulip Server 10.4. A workaround for this issue involves denying access to /digest/.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 02 Jul 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the digest itself, contains a cross-site scripting (XSS) vulnerability in both topic names and channel names. This issue has been fixed in Zulip Server 10.4. A workaround for this issue involves denying access to /digest/. | |
Title | Zulip XSS in digest preview URL | |
Weaknesses | CWE-79 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-02T19:31:12.064Z
Updated: 2025-07-02T19:37:15.550Z
Reserved: 2025-06-18T03:55:52.035Z
Link: CVE-2025-52559

Updated: 2025-07-02T19:37:04.875Z

Status : Awaiting Analysis
Published: 2025-07-02T20:15:31.443
Modified: 2025-07-03T15:13:53.147
Link: CVE-2025-52559

No data.