Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.
{
"unresolved_ranges": [
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "9.0"
},
{
"last_affected": "9.0"
}
],
"vendor_product": "debian:debian_linux"
}
]
}{
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:mumble:mumble:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.3.4"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-27229.json"
"2026-07-09T00:13:15Z"
[
{
"signature_version": "v1",
"source": "https://github.com/mumble-voip/mumble/commit/e59ee87abe249f345908c7d568f6879d16bfd648",
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2021-27229-43ff6295",
"digest": {
"length": 235.0,
"function_hash": "65394302460783050181570692291240513141"
},
"target": {
"file": "src/mumble/ConnectDialog.cpp",
"function": "ConnectDialog::on_qaUrl_triggered"
}
},
{
"signature_version": "v1",
"source": "https://github.com/mumble-voip/mumble/commit/e59ee87abe249f345908c7d568f6879d16bfd648",
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2021-27229-9598d386",
"digest": {
"line_hashes": [
"70232847151359564456171497302430397879",
"118246664800755243633469300694518903283",
"204380696076314686599292659447017158641",
"4568989370343213662826175788362273508",
"99591226523144294550551577742778135793",
"138481416414352192922181994546856922670",
"224021822537927809128536996686578903981"
],
"threshold": 0.9
},
"target": {
"file": "src/mumble/ConnectDialog.cpp"
}
}
]