CVE-2025-31478
CVSS 3.1 Score 8.2 of 10 (high)
Details
Summary
CVE-2025-31478 is a vulnerability affecting the open-source team collaboration tool, Zulip. In certain configurations where account creation is limited to single-sign on authentication, but email authentication is disabled, a bug in the Zulip server allows unauthenticated users to create accounts. This issue can be exploited to gain access to the organization without having an account with the configured SSO backend or an invitation to join. The vulnerability is addressed in Zulip version 10.2, and a workaround involves implementing a requirement for invitations to join the organization to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.