PT-2026-1311 · Muffon · Muffon

Published

2026-01-05

·

Updated

2026-01-07

·

CVE-2025-55204

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions muffon versions prior to 2.3.0
Description muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a Remote Code Execution (RCE) issue. An attacker can exploit this by embedding a specially crafted muffon:// link on a website they control. When a victim visits the site or clicks the link, the browser triggers Muffon’s custom URL handler, causing the application to launch and process the URL, leading to RCE on the victim's machine without further interaction.
Recommendations Update to version 2.3.0 or later.

Exploit

Fix

RCE

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-55204
GHSA-GC3F-GQPH-522Q

Affected Products

Muffon