CVE-2024-44730: Mirotalk p2p

Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.

Affected products

Published 2024-10-11. Last modified 2026-06-17.