PT-2025-34742 · Unknown · Mihomo Party

Swayzgl1Tzyyy

·

Published

2025-08-26

·

Updated

2025-08-26

·

CVE-2025-9474

CVSS v3.1

4.5

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Mihomo Party versions through 1.8.1
Description: A vulnerability exists in Mihomo Party up to version 1.8.1 on macOS. The issue is related to the enableSysProxy function within the src/main/sys/sysproxy.ts file of the Socket Handler component, resulting in the creation of a temporary file with insecure permissions. The attack requires local access and is characterized by high complexity and difficult exploitability. The exploit is publicly available.
Recommendations: Versions prior to 1.8.1 are recommended. As a temporary workaround, consider restricting access to the enableSysProxy() function until a patch is available.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-9474

Affected Products

Mihomo Party