CVE-2025-56499: Metacubex Mihomo

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file.

Affected products

Published 2025-11-18. Last modified 2026-07-29.