Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the digest itself, contains a cross-site scripting (XSS) vulnerability in both topic names and channel names. This issue has been fixed in Zulip Server 10.4. A workaround for this issue involves denying access to /digest/.
History

Wed, 02 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Jul 2025 19:45:00 +0000

Type Values Removed Values Added
Description Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the digest itself, contains a cross-site scripting (XSS) vulnerability in both topic names and channel names. This issue has been fixed in Zulip Server 10.4. A workaround for this issue involves denying access to /digest/.
Title Zulip XSS in digest preview URL
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-02T19:31:12.064Z

Updated: 2025-07-02T19:37:15.550Z

Reserved: 2025-06-18T03:55:52.035Z

Link: CVE-2025-52559

cve-icon Vulnrichment

Updated: 2025-07-02T19:37:04.875Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-02T20:15:31.443

Modified: 2025-07-03T15:13:53.147

Link: CVE-2025-52559

cve-icon Redhat

No data.