CVE-2026-24050

medium

Description

Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. Exploiting these vulnerabilities required the user explicitly interacting with the problematic object. This vulnerability is fixed in 11.5.

References

https://zulip.readthedocs.io/en/latest/overview/changelog.html#zulip-server-11-5

https://github.com/zulip/zulip/security/advisories/GHSA-56qv-8823-6fq9

https://github.com/zulip/zulip/releases/tag/11.5

https://github.com/zulip/zulip/commit/e6093d9e4788f4d82236d856c5ed7b16767886a7

Details

Source: Mitre, NVD

Published: 2026-02-06

Updated: 2026-02-23

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.4

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

CVSS v4

Base Score: 4.8

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Severity: Medium

EPSS

EPSS: 0.00043