Critical severity9.8NVD Advisory· Published Feb 5, 2021· Updated Jun 17, 2026
CVE-2020-10857
CVE-2020-10857
Description
Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:zulip:zulip_desktop:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:zulip:zulip_desktop:*:*:*:*:*:*:*:*range: <5.0.0
- (no CPE)
Patches
Vulnerability mechanics
References
1- blog.zulip.com/2020/04/01/zulip-desktop-5-0-0-security-release/nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.