CVE-2025-31478

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Apr 16, 2025
Updated: Apr 17, 2025
CWE ID 287

Summary

CVE-2025-31478 is a vulnerability affecting the open-source team collaboration tool, Zulip. In certain configurations where account creation is limited to single-sign on authentication, but email authentication is disabled, a bug in the Zulip server allows unauthenticated users to create accounts. This issue can be exploited to gain access to the organization without having an account with the configured SSO backend or an invitation to join. The vulnerability is addressed in Zulip version 10.2, and a workaround involves implementing a requirement for invitations to join the organization to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share