Local Privilege Escalation in Clash Verge Rev Product by Clash Verge
CVE-2025-50505

Currently unrated

Key Information:

Vendor
CVE Published:
7 October 2025

What is CVE-2025-50505?

The Clash Verge Rev product (versions up to 2.2.3) contains a vulnerability that enables local privilege escalation. This issue arises from the forced installation of system services (clash-verge-service) by default, which makes it possible for local users to exploit the unauthorized HTTP API endpoint '/start_clash'. Attackers are able to submit arbitrary 'bin_path' parameters that are executed directly by the service process, leading to potential unauthorized access and escalation of privileges within the affected system.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-50505 : Local Privilege Escalation in Clash Verge Rev Product by Clash Verge