cvedb.io
CVE-2025-30368
LOW · CVSS 2.7
EPSS exploitation probability: 0%
Published 2025-03-31T17:15:42.320 · Last modified 2026-06-17T09:08:35.830

Summary

Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an administrator of any organization was incorrectly allowed to delete an export of a different organization. This is fixed in Zulip Server 10.1.

Affected products

zulip — zulip

Does this affect you?

Add your gear to cvedb and we'll alert you only when zulip ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.