CVE-2025-9474

A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file src/main/sys/sysproxy.ts of the component Socket Handler. The manipulation results in creation of temporary file with insecure permissions. The attack requires a local approach. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit is now public and may be used.

Scoring

Severity
LOW
CVSS base score
4.5
CVSS vector
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
EPSS probability
0.14%
CWE
CWE-378, CWE-377
Published
2025-08-26
Last modified
2026-03-12

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs