BigBlueButton Open Redirect Vulnerability in ApiController

Vulnerability

An open redirect vulnerability has been identified in BigBlueButton versions 3.0.x prior to 3.0.20. The issue arises in the ApiController, where the errorRedirectUrl parameter is not properly validated before being used in the respondWithRedirect function. This lack of validation allows for untrusted URLs to be redirected to, potentially leading users to malicious sites. Organizations that upgraded from BigBlueButton 2.7.x to 3.0.x are particularly affected, as a code change in the new version introduced this redirect behavior for validation errors.

Impact

Exploitation of this vulnerability allows for open redirect behavior, where users can be sent to untrusted sites via manipulated redirect URLs. This could be used in phishing attacks or to bypass security controls that rely on URL validation.

Remediation

Users are advised to upgrade to BigBlueButton version 3.0.20, which addresses this vulnerability. Instructions for upgrading can be found in the BigBlueButton documentation.

Added: Feb 25, 2026, 7:35 PM
Updated: Feb 25, 2026, 7:35 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.2
exploitability
6.7
remediation
7.7
relevance
3.2
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.