PoC Index

CVE-2020-25019

HIGH 7.5EPSS 1.0%

jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
1.02% chance of exploitation in the next 30 days, 61th percentile
Published
2020-08-29
Updated
2025-11-17

Proof-of-concept exploits (1)

References

Related