7.1 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): HIGH
- Availability impact (A): LOW
by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
removed
9 packages
- matrix-zulip-bridge
- zulip
- zulip-term
- python312Packages.zulip
- python313Packages.zulip
- python314Packages.zulip
- python312Packages.zulip-emoji-mapping
- python313Packages.zulip-emoji-mapping
- python314Packages.zulip-emoji-mapping
- @LeSuisse dismissed
Zulip Vulnerable to Modification of Payment Method (Stripe Default Card) by Non-Billing Users
Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card update session during an upgrade flow was accessible to users with only organization member privileges. When the associated Stripe Checkout session is completed, the Stripe webhook updates the organization’s default payment method. Because no billing-specific authorization check is enforced, a regular (non-billing) member can change the organization’s payment method. This vulnerability affected the Zulip Cloud payment processing system, and has been patched as of commit bf28c82dc9b1f630fa8e9106358771b20a0040f7. Self-hosted deploys are no longer affected and no patch or upgrade is required for them.
References
- https://github.com/zulip/zulip/security/advisories/GHSA-vhhx-84f7-rc8j x_refsource_CONFIRM
- https://github.com/zulip/zulip/commit/bf28c82dc9b1f630fa8e9106358771b20a0040f7 x_refsource_MISC
Affected products
- ==< bf28c82dc9b1f630fa8e9106358771b20a0040f7
Ignored packages (9)
pkgs.zulip
Desktop client for Zulip Chat
pkgs.zulip-term
Zulip's official terminal client
-
nixos-unstable 0.7.0-unstable-2025-05-19
- nixpkgs-unstable 0.7.0-unstable-2025-05-19
- nixos-unstable-small 0.7.0-unstable-2026-02-10
-
nixos-25.11 0.7.0-unstable-2025-05-19
- nixos-25.11-small 0.7.0-unstable-2025-05-19
- nixpkgs-25.11-darwin 0.7.0-unstable-2025-05-19
pkgs.matrix-zulip-bridge
Matrix puppeting appservice bridge for Zulip
pkgs.python312Packages.zulip
Bindings for the Zulip message API
pkgs.python313Packages.zulip
Bindings for the Zulip message API
pkgs.python314Packages.zulip
Bindings for the Zulip message API
pkgs.python312Packages.zulip-emoji-mapping
Get emojis by Zulip names
pkgs.python313Packages.zulip-emoji-mapping
Get emojis by Zulip names
pkgs.python314Packages.zulip-emoji-mapping
Get emojis by Zulip names