A path traversal vulnerability was discovered in Zulip, an open-source team collaboration tool, affecting versions from 1.4.0 to before 11.6. The vulnerability exists in the ./manage.py import function, which reads arbitrary files from the server filesystem via path traversal in uploads/records.json. A crafted export tarball causes the server to copy any file the zulip user can read into the uploads direc [truncated]
CVE-2026-25742 is a vulnerability in Zulip, an open-source team collaboration tool. Even after disabling spectator access, attachments from web-public streams remain accessible anonymously. This issue, patched in version 11.6, allows retrieval of file contents and topic history for web-public streams without authentication. The vulnerability exists due to improper access controls on attachments and topic [truncated]