Security Flaw in Zulip Collaboration Tool Affects Account Creation Process
CVE-2025-31478
8.2HIGH
What is CVE-2025-31478?
A vulnerability in the Zulip collaboration tool allows unauthorized account creation in organizations with SSO authentication. When the EmailAuthBackend is disabled, users can potentially register without proper SSO credentials. This flaw highlights the importance of restricting account creation through invitations, ensuring that only authorized users can access the organization.
Affected Version(s)
zulip < 10.2