CVE-2025-9474 Details
Description
A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file src/main/sys/sysproxy.ts of the component Socket Handler. The manipulation results in creation of temporary file with insecure permissions. The attack requires a local approach. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit is now public and may be used.
A local privilege escalation vulnerability has been identified in Mihomo Party versions prior to 1.8.1 on macOS. The issue arises in the Socket Handler component, specifically within the 'enableSysProxy' function of 'src/main/sys/sysproxy.ts'. The vulnerability allows the creation of a temporary file with insecure permissions, which can be exploited by local attackers. The root cause is the exposure of a root-owned UNIX socket at '/tmp/mihomo-party-helper.sock', which has world-readable and writable permissions. This socket accepts unauthenticated HTTP requests to modify system-wide proxy settings, enabling attackers to route traffic through an attacker-controlled server, potentially leading to man-in-the-middle attacks and data exfiltration.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 26, 2025CISA-ADP
Assessed Aug 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/SwayZGl1tZyyy/n-days/blob/main/mihomo-party/README.md | [email protected] | ExploitTechnical Description |
| https://github.com/SwayZGl1tZyyy/n-days/blob/main/mihomo-party/README.md#proof-of-concept-1 | [email protected] | ExploitTechnical Description |
| https://vuldb.com/?ctiid.321343 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.321343 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.634656 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-377 | Insecure Temporary File | [email protected] |
| CWE-378 | Creation of Temporary File With Insecure Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Mihomo Party | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Aug 26, 2025 | New CVE Received | [email protected] |
Volerion