Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Bron1E

#33912of 55,135
7.8Total CVSS
Vulnerabilities · 1
PT-2025-40998
7.8
2025-10-07
Unknown · Clash Verge · CVE-2025-50505
**Name of the Vulnerable Software and Affected Versions** Clash Verge versions through 2.2.3 **Description** The software installs system services (`clash-verge-service`) by default and exposes functions through an unauthorized HTTP API. Specifically, the `/start clash` API endpoint allows local users to submit arbitrary `bin path` parameters. These parameters are directly passed to the service process for execution, potentially leading to local privilege escalation. **Recommendations** Update to a version beyond 2.2.3.