PT-2025-40998 · Unknown · Clash Verge

Bron1E

·

Published

2025-10-07

·

Updated

2026-01-21

·

CVE-2025-50505

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Clash Verge versions through 2.2.3
Description The software installs system services (clash-verge-service) by default and exposes functions through an unauthorized HTTP API. Specifically, the /start clash API endpoint allows local users to submit arbitrary bin path parameters. These parameters are directly passed to the service process for execution, potentially leading to local privilege escalation.
Recommendations Update to a version beyond 2.2.3.

Exploit

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-50505

Affected Products

Clash Verge