VulnerabilityAnalyzed
CVE-2026-24050
From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names.
LOW 1.1EPSS 0.24%
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. Exploiting these vulnerabilities required the user explicitly interacting with the problematic object. This vulnerability is fixed in 11.5.
- CVSS 4.0
- 1.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- zulip/zulip server
- Source
- security-advisories@github.com
References
- https://github.com/zulip/zulip/commit/e6093d9e4788f4d82236d856c5ed7b16767886a7Patch
- https://github.com/zulip/zulip/releases/tag/11.5Release Notes
- https://github.com/zulip/zulip/security/advisories/GHSA-56qv-8823-6fq9Vendor Advisory
- https://zulip.readthedocs.io/en/latest/overview/changelog.html#zulip-server-11-5Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.