Disclosure summary
muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in. An attacker can exploit this issue by embedding a specially crafted `muffon://` link on any website they control. When a victim visits the site or clicks the link, the browser triggers Muffon’s custom URL handler, causing the application to launch and process the URL. This leads to RCE on the victim's machine without further interaction. Version 2.3.0 patches the issue.
Source-reported weakness categories
CWE-94, CWE-79
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2025-55204
Open original source · Updated Oct 07, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| muffon | muffon | * {"versionEndExcluding":"2.3.0"} |
Original records & references
- NIST NVD record
- CVE Program record
- drive.google.com — Exploit
- github.com — Product, Release Notes
- github.com — Exploit, Third Party Advisory
PUBLISHED 2026-01-05T13:15:42-05:00
MODIFIED 2026-10-07T06:10:00-04:00
INGESTED 2026-10-08T12:40:19-04:00