PT-2025-16904 · Zulip · Zulip

Timabbott

·

Published

2025-04-16

·

Updated

2026-01-23

·

CVE-2025-31478

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zulip versions prior to 10.2
Description A bug in the Zulip server allows account creation without authenticating with the configured Single Sign-On (SSO) authentication backend in organizations where account creation is limited solely by SSO authentication and email/password authentication is disabled. This issue can be exploited to create an account without having an account with the configured SSO authentication backend.
Recommendations For versions prior to 10.2, update to version 10.2 to resolve the issue. As a temporary workaround, consider requiring invitations to join the organization to prevent the vulnerability from being accessed.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-31478
GHSA-QXFV-J6VG-5RQC

Affected Products

Zulip