Vulnerability record · CVE-2025-30368 · published 31 March 2025
CVE-2025-30368: Zulip vulnerability
Zulip · Zulip
Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an administrator of any organization was incorrectly allowed to delete an export of a different organization. This is fixed in Zulip Server 10.1.
Description
Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an administrator of any organization was incorrectly allowed to delete an export of a different organization. This is fixed in Zulip Server 10.1.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/zulip/zulip/commit/07dcee36b2a34d63429d7a706f880628cf3433df | Patch |
| https://github.com/zulip/zulip/security/advisories/GHSA-rmhr-5ffq-qcrc | PatchThird Party Advisory |
| https://zulip.readthedocs.io/en/latest/overview/changelog.html#zulip-server-10-1 | Release Notes |
Track CVE-2025-30368 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-30368), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.