CVE-2025-30368
Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an administrator of any organization was incorrectly allowed to delete an export of a different organization. This is fixed in Zulip Server 10.1.
- Affected products
- Zulip Server
- Zulip
- = 10.0
- Fix
- Available
- CVSS 3.1
- 2.7 LOW
- EPSS
- 0.3% (26th percentile)
- Weakness
- CWE-566
- NVD status
- Analyzed
- Published
- 2025-03-31
CVE-2025-30368 at NVD
No indexed exploits for CVE-2025-30368 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-30368 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.