CVE-2025-9474

MEDIUM

Mihomo Party <1.8.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file src/main/sys/sysproxy.ts of the component Socket Handler. The manipulation results in creation of temporary file with insecure permissions. The attack requires a local approach. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit is now public and may be used.

Scores

CVSS v3 4.5
EPSS 0.0002
EPSS Percentile 4.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-377 CWE-378
Status published
Products (2)
Mihomo/Party 1.8.0
Mihomo/Party 1.8.1
Published Aug 26, 2025
Tracked Since Feb 18, 2026