Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allows attackers to hijack the OAuth authentication window for Microsoft accounts. This is fixed in version 2.0.10532. No known workarounds are available.
History

Fri, 14 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Nov 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Jitsi
Jitsi meet
Vendors & Products Jitsi
Jitsi meet

Thu, 13 Nov 2025 22:00:00 +0000

Type Values Removed Values Added
Description Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allows attackers to hijack the OAuth authentication window for Microsoft accounts. This is fixed in version 2.0.10532. No known workarounds are available.
Title Jitsi Meet has DOM Redirect on Microsoft OAuth Flow
Weaknesses CWE-601
References
Metrics cvssV4_0

{'score': 2.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-13T21:48:08.692Z

Updated: 2025-11-14T16:03:57.905Z

Reserved: 2025-11-10T22:29:34.874Z

Link: CVE-2025-64754

cve-icon Vulnrichment

Updated: 2025-11-14T15:58:20.635Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-13T22:15:52.920

Modified: 2025-11-14T16:42:03.187

Link: CVE-2025-64754

cve-icon Redhat

No data.