CVE-2025-55204

HIGH

muffon < 2.3.0 - Remote Code Execution via Crafted muffon:// URL Handler

Title source: llm
STIX 2.1

Description

muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in. An attacker can exploit this issue by embedding a specially crafted `muffon://` link on any website they control. When a victim visits the site or clicks the link, the browser triggers Muffon’s custom URL handler, causing the application to launch and process the URL. This leads to RCE on the victim's machine without further interaction. Version 2.3.0 patches the issue.

References (3)

Core 3

Scores

CVSS v3 8.8
EPSS 0.0058
EPSS Percentile 43.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79 CWE-94
Status published
Products (1)
muffon/muffon < 2.3.0
Published Jan 05, 2026
Tracked Since Feb 18, 2026