Zulip

zulip.com
Zulip

Open source team chat organized around topic-based threading, which keeps busy conversations easier to follow than channel-only tools. Can be self-hosted, or used as a paid cloud service. The threading model takes some getting used to.

Open Source

Zulip Source Code

Author

zulip

Description

Zulip server and web application. Open-source team chat that helps teams stay productive and focused.

#apache#chat#collaboration#electron#foss#free#javascript#python#python3#react-native#slack#zulip

Homepage

https://zulip.com

License

Apache-2.0

Created

25 Sept 15

Last Updated

29 Jul 26

Latest version

shared-0.0.18

Primary Language

Python

Size

638,956 KB

Stars

25,573

Forks

10,006

Watchers

25,573

Language Usage

Language Usage

Star History

Star History

Top Contributors

Recent Commits

Zulip Security

6.6/10

Repo Security Summary

Updated 20 Jul 26

  • Code-Review 9/10
  • Packaging N/A
  • Maintained 10/10
  • CII-Best-Practices 0/10
  • Security-Policy 10/10
  • Dangerous-Workflow 10/10
  • Token-Permissions 10/10
  • License 10/10
  • Signed-Releases 0/10
  • Branch-Protection 1/10
  • Binary-Artifacts 10/10
  • Pinned-Dependencies 0/10
  • Fuzzing 0/10
  • SAST 10/10

Security Advisories (32)

  • medium Patched

    CVE-2026-40300 Message edit history visible in "moves only" policy through /api/v1/messages/{id}/history

  • medium Unpatched CVSS 6.1

    CVE-2026-26058 Path Traversal in Import

  • high Patched CVSS 7.1

    CVE-2026-25741 Modification of Payment Method (Stripe Default Card) by Non-Billing Users

  • medium Unpatched CVSS 5.3

    CVE-2026-25742 Anonymous File Access After Disabling Spectator Access

  • low Patched

    CVE-2026-24050 Stored XSS in user profile modal

  • medium Patched CVSS 6.8

    CVE-2025-52559 XSS in digest preview URL

  • medium Patched

    CVE-2025-47930 Access control bypass for restrictions on creation of specific channel types

  • high Patched CVSS 8.2

    CVE-2025-31478 Authentication backend configuration bypass

  • low Patched CVSS 2.7

    CVE-2025-30368 Organization exports can be deleted by administrators of a different organization

  • low Patched CVSS 2.7

    CVE-2025-30369 Custom profile fields can be deleted by administrators of a different organization

  • medium Patched

    CVE-2025-27149 "Public data" administrative data exports can leak metadata for non-exported messages and client user agent strings

  • medium Patched CVSS 4.3

    CVE-2025-25195 Events can leak private channel names

  • medium Patched

    CVE-2024-56136 /api/v1/jwt/fetch_api_key endpoint can leak if an email address has an account

  • high Patched

    CVE-2024-27286 Moving messages from public to private streams may leave them accessible

  • medium Patched CVSS 4.3

    CVE-2024-21630 Non-admins can invite new users to streams they would not otherwise be able to add existing users to

  • medium Patched CVSS 4.3

    CVE-2023-47642 Invalid metadata access for formerly subscribed streams.

  • high Patched CVSS 8.2

    CVE-2023-33186 Cross-site scripting vulnerability in Zulip Server development branch via topic tooltip

  • medium Patched CVSS 4.3

    CVE-2023-32677 Users who can send invitations can add users to streams during invitation, even if they cannot add users to streams at other times

  • high Patched CVSS 7.5

    CVE-2023-28623 Unauthorized user can register an account in specific configurations involving LDAP and another external authentication backend

  • medium Patched CVSS 5.4

    CVE-2023-22735 User uploads proxied from S3 lack `Content-Security-Policy` headers, may be served with `Content-Disposition: inline`

  • medium Patched CVSS 6.5

    CVE-2023-32678 Insufficient authorization check for edition/deletion of messages and topics in private streams by former subscribers

  • medium Patched CVSS 4.8

    CVE-2022-41914 Non-constant-time SCIM token comparison in Zulip Server

  • medium Patched CVSS 4.3

    CVE-2022-36048 IP address leak via image proxy bypass in Zulip Server

  • medium Patched CVSS 5.4

    CVE-2022-31168 Insufficient authorization check for changing bot roles in Zulip Server

  • medium Patched CVSS 4.9

    CVE-2022-31134 Public data export contains attachments that are non-public

  • low Patched CVSS 2

    CVE-2022-31017 Zulip Server exposes edit events for old messages to new subscribers in protected-history streams

  • low Patched

    CVE-2022-24751 Race condition in user deactivation allows continued API access

  • medium Patched CVSS 4.6

    CVE-2022-23656 Cross-site scripting vulnerability in Zulip Server development branch via tooltip

  • high Patched CVSS 7.2

    CVE-2022-21706 Multi-use invitations can grant access to other organizations

  • high Patched CVSS 8.6

    CVE-2021-43799 RabbitMQ exposes ports with weak default secrets

  • medium Patched

    CVE-2021-43791 Ineffective expiration validation for invitation links

  • medium Patched CVSS 4.3

    CVE-2021-41115 Regular expression denial-of-service in linkifiers

Zulip Website

Website

Zulip โ€” organized team chat

Zulip is an organized team chat app for distributed teams of all sizes.

Redirects

Does not redirect

Security Checks

All 65 security checks passed

Server Details

  • IP Address 34.225.147.149
  • Hostname ec2-34-225-147-149.compute-1.amazonaws.com
  • Location Ashburn, Virginia, United States of America, NA
  • ISP Amazon Technologies Inc.
  • ASN AS16509

Associated Countries

  • US US
  • CA CA

Safety Score

Website marked as safe

100%

Blacklist Check

zulip.com was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

Zulip Android App

APK Info

De-Googled Compatibility

Native 4.00 / 4 1 ratings
microG 4.00 / 4 1 ratings

Tested on Android 15โ€“16 ยท Updated 17 May 26 ยท View on Plexus โ†’

Trackers

  • Sentry

Permissions

  • Access Network State
  • Access Wifi State
  • Internet
  • Post Notifications
  • Read External Storage
  • Vibrate
  • Wake Lock
  • Write External Storage

Zulip Reviews

More Team Collaboration

  • Privacy-focused messenger using the Matrix protocol. The Element client allows for group chat rooms, media sharing voice and video group calls.

  • An IRC-based solution is another option, being decentralized there is no point of failure, and it's easy to self-host. However it's important to keep security in mind while configuring your IRC instance and ensure that channels are properly encrypted - IRC tends to be better for open communications. There's a variety of clients to choose from - popular options include: The Longe (Web-based), HexChat (Linux), Pidgin (Linux), WeeChat (Linux, terminal-based), IceChat (Windows), XChat Aqua (MacOS), Palaver (iOS) and Revolution (Android).

  • Mattermost has an open source edition, which can be self-hosted. It makes a good Slack alternative, with native desktop, mobile and web apps and a wide variety of integrations.

  • Secure group communications, with the option to be used over Tor or I2P. Fast intuitive group and 1-to-1 chats with text and rich media using decentralized chat rooms, with a mail feature for delivering messages to offline contacts. A channels feature makes it possible for members of different teams to stay up-to-date with each other, and to share files. Also includes built-in forums, link aggregations, file sharing and voice and video calling. RetroShare is a bit more complex to use than some alternatives, and the UI is quite retro, so may not be appropriate for a non-technical team.

  • Easy-to-deploy, self-hosted team collaboration platform with stable, feature-rich cross-platform client apps. The UI is fast, good looking and intuitive, so very little technical experience is needed for users of the platform. Rocket.Chat's feature set is similar to Slack's, making it a good replacement for any team looking to have greater control over their data.

About the Data: Zulip

Change History

API

You can access Zulip's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/zulip

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share Zulip

Help your friends compare Team Collaboration, and pick privacy-respecting software and services.
Share Zulip and Awesome Privacy with your network!

View Team Collaboration (6)