Data Exposure Flaw in Zulip Server Affects Open-Source Team Chat
CVE-2025-27149
4.6MEDIUM
What is CVE-2025-27149?
The Zulip server, an open-source team collaboration tool, suffered from a data exposure flaw prior to version 10.0. This vulnerability allowed organization administrators to access sensitive information unintentionally included in data exports. Metadata pertaining to user-agent types from various integrations, as well as private channel topics, were disclosed, despite the administrators lacking the necessary permissions to view this data. Notably, this metadata included details about user interactions in group DMs without any member consent for export. The issue has been resolved in version 10.0, providing enhanced protection for user privacy.
Affected Version(s)
zulip >= 2.1.0, < 10.0