CVE-2020-25019: Jitsi Meet Electron

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.

Affected products

  • Jitsi Meet Electron: before 2.3.0 (fixed in 2.3.0)

Published 2020-08-29. Last modified 2026-06-17.