Security Flaw in Zulip Collaboration Tool Affects Account Creation Process
CVE-2025-31478
8.2HIGH
What is CVE-2025-31478?
A vulnerability in the Zulip collaboration tool allows unauthorized account creation in organizations with SSO authentication. When the EmailAuthBackend is disabled, users can potentially register without proper SSO credentials. This flaw highlights the importance of restricting account creation through invitations, ensuring that only authorized users can access the organization.
Affected Version(s)
zulip < 10.2
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
