CVE-2025-13433

HIGH

Muse Group MuseHub 2.1.0.1567 - Path Traversal

Title source: llm
STIX 2.1

Description

A security flaw has been discovered in Muse Group MuseHub 2.1.0.1567. The affected element is an unknown function of the file C:\Program Files\WindowsApps\Muse.MuseHub_2.1.0.1567_x64__rb9pth70m6nz6\Muse.Updater.exe of the component Windows Service. The manipulation results in unquoted search path. The attack is only possible with local access. A high complexity level is associated with this attack. The exploitability is described as difficult. The vendor was contacted early about this disclosure but did not respond in any way.

Scores

CVSS v3 7.0
EPSS 0.0002
EPSS Percentile 4.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-426 CWE-428
Status published
Products (1)
Muse Group/MuseHub 2.1.0.1567
Published Nov 20, 2025
Tracked Since Feb 18, 2026