PT-2026-6771 · Zulip · Zulip

Joshua Rogers

·

Published

2026-02-06

·

Updated

2026-02-06

·

CVE-2026-24050

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zulip versions 5.0 through 11.4
Description Zulip, an open-source team collaboration tool, had a stored cross-site scripting (XSS) issue in group names or channel names due to certain administrative actions on the user profile. Exploitation required user interaction with the affected object.
Recommendations Update to version 11.5 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-24050
GHSA-56QV-8823-6FQ9

Affected Products

Zulip