Security Flaw in Zulip Collaboration Tool Affects Account Creation Process
CVE-2025-31478

8.2HIGH

Key Information:

Vendor

Zulip

Status
Vendor
CVE Published:
16 April 2025

What is CVE-2025-31478?

A vulnerability in the Zulip collaboration tool allows unauthorized account creation in organizations with SSO authentication. When the EmailAuthBackend is disabled, users can potentially register without proper SSO credentials. This flaw highlights the importance of restricting account creation through invitations, ensuring that only authorized users can access the organization.

Affected Version(s)

zulip < 10.2

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.