Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-52559


Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the digest itself, contains a cross-site scripting (XSS) vulnerability in both topic names and channel names. This issue has been fixed in Zulip Server 10.4. A workaround for this issue involves denying access to /digest/.


Published

2025-07-02T20:15:31.443

Last Modified

2025-10-02T01:51:09.033

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.8 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zulip zulip_server < 10.4 Yes
Application zulip zulip_server 2.0.0 Yes

References