CVE 2.7 LOW

Jitsi Meet has DOM Redirect on Microsoft OAuth Flow_CVE-2025-64754

2.7 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U

Description

Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allows attackers to hijack the OAuth authentication window for Microsoft accounts. This is fixed in version 2.0.10532. No known workarounds are available.

Basic Information

ID CVE-2025-64754
Source GitHub_M
Published Nov 13, 2025 at 21:48

Affected Product

Vendor jitsi
Product jitsi-meet
Version < 2.0.10532
Affected Versions jitsi jitsi-meet < 2.0.10532

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.