PT-2026-30233 · Zulip · Zulip

·

CVE-2026-26058

·

Published

2026-04-03

·

Updated

2026-07-24

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zulip versions 1.4.0 through 11.5
Description An issue exists where the ./manage.py import command allows the reading of arbitrary files from the server filesystem. This occurs due to path traversal in uploads/records.json, where a specially crafted export tarball can force the server to copy any file accessible by the zulip user into the uploads directory during the import process. Path traversal is a technique used to access files and directories that are stored outside the web root folder.
Recommendations Update to version 11.6.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26058
GHSA-XM5C-C6MP-3956

Affected Products

Zulip