Local Privilege Escalation in Clash Verge Rev Product by Clash Verge
CVE-2025-50505
Currently unrated
What is CVE-2025-50505?
The Clash Verge Rev product (versions up to 2.2.3) contains a vulnerability that enables local privilege escalation. This issue arises from the forced installation of system services (clash-verge-service) by default, which makes it possible for local users to exploit the unauthorized HTTP API endpoint '/start_clash'. Attackers are able to submit arbitrary 'bin_path' parameters that are executed directly by the service process, leading to potential unauthorized access and escalation of privileges within the affected system.