CPE
Clash Verge Rev versions 2.2.3 and earlier are vulnerable to unauthenticated command execution via an API endpoint that can lead to local privilege escalation or remote code execution.