PT-2025-34742 · Unknown · Mihomo Party
Swayzgl1Tzyyy
·
Published
2025-08-26
·
Updated
2025-08-26
·
CVE-2025-9474
CVSS v3.1
4.5
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
Mihomo Party versions through 1.8.1
Description:
A vulnerability exists in Mihomo Party up to version 1.8.1 on macOS. The issue is related to the
enableSysProxy function within the src/main/sys/sysproxy.ts file of the Socket Handler component, resulting in the creation of a temporary file with insecure permissions. The attack requires local access and is characterized by high complexity and difficult exploitability. The exploit is publicly available.Recommendations:
Versions prior to 1.8.1 are recommended. As a temporary workaround, consider restricting access to the
enableSysProxy() function until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mihomo Party