Jitsi Meet OAuth Authentication Hijacking Vulnerability for Microsoft Accounts

Vulnerability

A vulnerability in Jitsi Meet versions prior to 2.0.10532 allows attackers to hijack the OAuth authentication window for Microsoft accounts. This issue has been addressed in version 2.0.10532, and no known workarounds are available.

Impact

Exploitation of this vulnerability allows for hijacking the OAuth authentication process for Microsoft accounts, potentially leading to unauthorized access or actions on behalf of the user.

Remediation

Users are advised to upgrade to Jitsi Meet version 2.0.10532 or later.

Added: Nov 13, 2025, 10:17 PM
Updated: Nov 13, 2025, 10:17 PM

Vulnerability Rating

Custom Algorithm
spread
8.8
impact
0.6
exploitability
6.5
remediation
7.7
relevance
1.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.