CVE-2025-56499: Metacubex Mihomo
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file.
Affected products
- Metacubex Mihomo: version 1.19.11 only
Published 2025-11-18. Last modified 2026-07-29.