Логотип exploitDog
bind:CVE-2025-50505
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-50505

Количество 2

Количество 2

nvd логотип

CVE-2025-50505

29 дней назад

Clash Verge Rev thru 2.2.3 forces the installation of system services(clash-verge-service) by default and exposes key functions through the unauthorized HTTP API `/start_clash`, allowing local users to submit arbitrary bin_path parameters and pass them directly to the service process for execution, resulting in local privilege escalation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-225v-733h-9gwv

29 дней назад

Clash Verge Rev thru 2.2.3 forces the installation of system services(clash-verge-service) by default and exposes key functions through the unauthorized HTTP API `/start_clash`, allowing local users to submit arbitrary bin_path parameters and pass them directly to the service process for execution, resulting in local privilege escalation.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-50505

Clash Verge Rev thru 2.2.3 forces the installation of system services(clash-verge-service) by default and exposes key functions through the unauthorized HTTP API `/start_clash`, allowing local users to submit arbitrary bin_path parameters and pass them directly to the service process for execution, resulting in local privilege escalation.

CVSS3: 7.8
0%
Низкий
29 дней назад
github логотип
GHSA-225v-733h-9gwv

Clash Verge Rev thru 2.2.3 forces the installation of system services(clash-verge-service) by default and exposes key functions through the unauthorized HTTP API `/start_clash`, allowing local users to submit arbitrary bin_path parameters and pass them directly to the service process for execution, resulting in local privilege escalation.

CVSS3: 7.8
0%
Низкий
29 дней назад

Уязвимостей на страницу