A AegiFlow
MEDIUMCVSS 6.5

CVE-2025-56499

CVE-2025-56499 updated by NVD

Modified
2026-07-31
Sources
nvd

Summary

Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file.

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.