PT-2025-40998 · Unknown · Clash Verge

·

CVE-2025-50505

·

Published

2025-10-07

·

Updated

2026-01-21

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Clash Verge versions through 2.2.3
Description The software installs system services (clash-verge-service) by default and exposes functions through an unauthorized HTTP API. Specifically, the /start clash API endpoint allows local users to submit arbitrary bin path parameters. These parameters are directly passed to the service process for execution, potentially leading to local privilege escalation.
Recommendations Update to a version beyond 2.2.3.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-50505

Affected Products

Clash Verge