CVE-2024-44081: 8x8 Jitsi Meet

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an arbitrary URL if a message from another participant contains a URL encoded in the expected format.

Affected products

  • 8x8 Jitsi Meet: before 2.0.9779 (fixed in 2.0.9779)

Published 2024-10-29. Last modified 2026-06-17.