CVE-2025-25195

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 13, 2025
CWE ID 200

Summary

CVE-2025-25195 is a vulnerability affecting Zulip, an open-source team chat application. A weekly cron job, added in commit 50256f48314250978f521ef439cafa704e056539, demotes inactive channels after 180 days of no traffic. However, when this event was triggered, it was broadcasted to all users in the organization, revealing the name of the private channel. An additional issue was discovered where the same commit allowed clients to be notified when channels transitioned from inactive to active. The first message sent to a private channel, previously marked as inactive, would leak an event containing the channel name to all organization members. Commits 75be449d456d29fef27e9d1828bafa30174284b4 and a2a1a7f8d152296c8966f1380872c0ac69e5c87e addressed these issues. This vulnerability was exclusive to the `main` branch and did not impact any published versions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share