Data Exposure Flaw in Zulip Server Affects Open-Source Team Chat
CVE-2025-27149
What is CVE-2025-27149?
The Zulip server, an open-source team collaboration tool, suffered from a data exposure flaw prior to version 10.0. This vulnerability allowed organization administrators to access sensitive information unintentionally included in data exports. Metadata pertaining to user-agent types from various integrations, as well as private channel topics, were disclosed, despite the administrators lacking the necessary permissions to view this data. Notably, this metadata included details about user interactions in group DMs without any member consent for export. The issue has been resolved in version 10.0, providing enhanced protection for user privacy.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
zulip >= 2.1.0, < 10.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
