CVE-2019-18933: Zulip Server
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal API key stolen by an unprivileged attacker, allowing nearly full access to the user's account.
Affected products
- Zulip Zulip Server: from 1.7.0, before 2.0.7 (fixed in 2.0.7)
Published 2019-11-21. Last modified 2026-06-17.