Information Leakage Vulnerability in Zulip Team Chat Application
CVE-2025-25195
What is CVE-2025-25195?
An information leakage issue existed in the Zulip team chat application where notifications related to private channels were improperly sent to all users within an organization. When a private channel became inactive due to lack of traffic over 180 days, an event revealing the private channel's name was broadcasted to all users. This vulnerability compromised channel confidentiality and posed a risk of inadvertent exposure of private conversation topics. The issue was rectified in subsequent commits, preventing unauthorized visibility of channel names within the user base.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
zulip >= 50256f48314250978f521ef439cafa704e056539, < 75be449d456d29fef27e9d1828bafa30174284b4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
