CVE-2025-53811
The configuration of Mosh-Pro on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivileged access to execute arbitrary code that inherits Mosh-Pro TCC (Transparency, Consent, and Control) permissions. Acquired resource access is limited to previously granted permissions by the user. Accessing other resources beyond previously granted TCC permissions will prompt the user for approval in the name of Mosh-Pro, potentially disguising attacker's malicious intent. This issue was detected in 1.3.2 version of Mosh-Pro. Since authors did not respond to messages from CNA, patching status is unknown.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.8
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.13%
- CWE
- CWE-276
- Published
- 2025-08-26
- Last modified
- 2026-08-31
Affected products
- Mosh-Pro Mosh-Pro
- Mosh-Pro Mosh-Pro
Weakness type
Related vulnerabilities
- CVE-2025-40585 — A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain
- CVE-2020-37129 — Memu Play 7.1.3 - Insecure Folder Permissions
- CVE-2026-21765 — HCL BigFix Platform is affected by insecure permissions on private cryptographic keys
- CVE-2025-62577 — ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged
- CVE-2025-12100 — MongoDB BI Connector ODBC driver installation via MSI may leave ACLs unset on custom installation directories
- CVE-2025-11575 — MongoDB Atlas SQL ODBC driver installation via MSI may leave ACLs unset on custom installation directories
- CVE-2025-11535 — MongoDB Connector for BI installation MSI leave ACLs unset on custom installation directories
- CVE-2025-10314 — Malicious Code Execution Vulnerability in Mitsubishi Small-Capacity UPS Shutdown Software FREQSHIP-mini for Windows