CVE 8.8 HIGH

muffon has One-click Remote Code Execution via XSS and Custom URL Handling_CVE-2025-55204

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in. An attacker can exploit this issue by embedding a specially crafted `muffon://` link on any website they control. When a victim visits the site or clicks the link, the browser triggers Muffon’s custom URL handler, causing the application to launch and process the URL. This leads to RCE on the victim's machine without further interaction. Version 2.3.0 patches the issue.

AI Analysis

One-click Remote Code Execution vulnerability via XSS and custom URL handling

Basic Information

ID CVE-2025-55204
Source GitHub_M
Published Jan 5, 2026 at 17:37

Affected Product

Vendor staniel359
Product muffon
Version < 2.3.0
Affected Versions staniel359 muffon < 2.3.0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor staniel359
Product muffon
Version < 2.3.0

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.