CVE-2020-25019

HIGH

jitsi-meet-electron < 2.3.0 - Unauthenticated Arbitrary URL Execution via shell.openExternal

Title source: llm
STIX 2.1

Description

jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.

Scores

CVSS v3 7.5
EPSS 0.0102
EPSS Percentile 59.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-345
Status published
Products (1)
jitsi/meet_electron < 2.3.0
Published Aug 29, 2020
Tracked Since Feb 18, 2026