216.73.217.22

CVE-2025-9474

· Published 26/08/2025 05:15 · Modified 26/08/2025 13:41

Labels: CVE-2025-9474 2025-08-26CVE-2025-9474CWE-377[email protected]

Essential information

Published
26/08/2025 05:15
Modified
26/08/2025 13:41
Author
Creator
CVSS
2.0 LOW (v3) 2.0 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file src/main/sys/sysproxy.ts of the component Socket Handler. The manipulation results in creation of temporary file with insecure permissions. The attack requires a local approach. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit is now public and may be used.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mihomo / mihomo party cpe:2.3:a:mihomo:mihomo_party:1.8.1:*:*:*:*:*:*:*

References