CVE-2020-15070: Zulip Server

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value.

Affected products

  • Zulip Zulip Server: before 2.1.7 (fixed in 2.1.7)

Published 2020-08-21. Last modified 2026-06-17.