Information Leakage Vulnerability in Zulip Team Chat Application
CVE-2025-25195
4.3MEDIUM
What is CVE-2025-25195?
An information leakage issue existed in the Zulip team chat application where notifications related to private channels were improperly sent to all users within an organization. When a private channel became inactive due to lack of traffic over 180 days, an event revealing the private channel's name was broadcasted to all users. This vulnerability compromised channel confidentiality and posed a risk of inadvertent exposure of private conversation topics. The issue was rectified in subsequent commits, preventing unauthorized visibility of channel names within the user base.
Affected Version(s)
zulip >= 50256f48314250978f521ef439cafa704e056539, < 75be449d456d29fef27e9d1828bafa30174284b4