VYPR

Meet Electron

by Jitsi

Source repositories

CVEs (2)

  • CVE-2020-25019HigAug 29, 2020
    risk 0.49cvss 7.5epss 0.01

    jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.

  • CVE-2026-92299HigSep 16, 2026
    risk 0.41cvss 7.4epss 0.00

    @jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMedia() picker, allowing any script in the meeting page to enumerate screens and windows. Attackers can call the jitsi-screen-sharing-get-sources IPC route to…