---
id: CVE-2025-55204
title: muffon is a cross-platform music streaming client for desktop
summary: >-
  muffon is a cross-platform music streaming client for desktop. Versions prior
  to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in. An
  attacker can exploit this issue by embedding a specially crafted `muffon://`
  link on…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
  - CWE-79
vendor: muffon
product: muffon
affected:
  - muffon < 2.3.0
patched:
  - muffon 2.3.0
published: '2026-01-05'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-55204'
references:
  - url: >-
      https://drive.google.com/file/d/1eCPCQ6leuVM_vecfofFv04c0t9isCBqR/view?usp=sharing
    label: security-advisories@github.com
  - url: 'https://github.com/staniel359/muffon/releases/tag/v2.3.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/staniel359/muffon/security/advisories/GHSA-gc3f-gqph-522q
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00705
epssPercentile: 0.51547
ingestedAt: '2026-09-30T22:27:27.690Z'
---

## Overview

muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in. An attacker can exploit this issue by embedding a specially crafted `muffon://` link on any website they control. When a victim visits the site or clicks the link, the browser triggers Muffon’s custom URL handler, causing the application to launch and process the URL. This leads to RCE on the victim's machine without further interaction. Version 2.3.0 patches the issue.

## Affected

- `muffon < 2.3.0`

## Remediation

Upgrade past the affected range:

- `muffon 2.3.0`
