LOW
Mihomo Party Socket sysproxy.ts enableSysProxy temp file
Published Aug 26, 2025
2.0
LOWCVSS 4.0
EPSS 0.14%
Description
A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file src/main/sys/sysproxy.ts of the component Socket Handler. The manipulation results in creation of temporary file with insecure permissions. The attack requires a local approach. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit is now public and may be used.
Affected products
-
- Version 1.8.0StatusaffectedConstraints-
- Version 1.8.1StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://github.com/SwayZGl1tZyyy/n-days/blob/main/mihomo-party/README.md related
- https://github.com/SwayZGl1tZyyy/n-days/blob/main/mihomo-party/README.md#proof-of-concept-1 exploit
- https://vuldb.com/?ctiid.321343 signaturepermissions-required
- https://vuldb.com/?id.321343 vdb-entrytechnical-description
- https://vuldb.com/?submit.634656 third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/SwayZGl1tZyyy/n-days/blob/main/mihomo-party/README.md | related | |
| https://github.com/SwayZGl1tZyyy/n-days/blob/main/mihomo-party/README.md#proof-of-concept-1 | exploit | |
| https://vuldb.com/?ctiid.321343 | signaturepermissions-required | |
| https://vuldb.com/?id.321343 | vdb-entrytechnical-description | |
| https://vuldb.com/?submit.634656 | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 26, 2025
Updated Sep 5, 2025
Reserved Aug 25, 2025
Link CVE-2025-9474
CISA Vulnrichment
Updated Aug 26, 2025