Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allows attackers to hijack the OAuth authentication window for Microsoft accounts. This is fixed in version 2.0.10532. No known workarounds are available.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 13 Nov 2025 22:00:00 +0000

Type Values Removed Values Added
Description Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allows attackers to hijack the OAuth authentication window for Microsoft accounts. This is fixed in version 2.0.10532. No known workarounds are available.
Title Jitsi Meet has DOM Redirect on Microsoft OAuth Flow
Weaknesses CWE-601
References
Metrics cvssV4_0

{'score': 2.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-13T21:48:08.692Z

Reserved: 2025-11-10T22:29:34.874Z

Link: CVE-2025-64754

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-13T22:15:52.920

Modified: 2025-11-13T22:15:52.920

Link: CVE-2025-64754

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.