Back to Database
Status published
Low
CVE-2025-64754
Jitsi Meet has DOM Redirect on Microsoft OAuth Flow
Vulnerability Description
Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allows attackers to hijack the OAuth authentication window for Microsoft accounts. This is fixed in version 2.0.10532. No known workarounds are available.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64754
Credits & Attribution
No credits recorded in the NVD database.
More from jitsi
View All →CVE-2022-36736
Jitsi-2.10.5550 was discovered to contain a vulnerability in its web...
Medium
6.1
CVE-2021-39215
Authentication Bypass: Forged Tokens Allow Access to Arbitrary Rooms
High
7.5
CVE-2021-39205
DOM-based XSS/Content Spoofing via Prototype Pollution
Medium
6.8
CVE-2021-26812
Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through...
Medium
6.1
CVE-2020-25019
jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron...
High
7.5
Affected Vendor
jitsi
View all reports →Affected Software
jitsi-meet
Vulnerable Versions:
< 2.0.10532
Timeline
Official Publish:
November 13th, 2025
Last Modified:
November 14th, 2025
Added to House:
July 22nd, 2026