{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/clash-verge/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:clash_verge_rev_project:clash_verge_rev:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2025-50505"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Clash Verge Rev (\u003c= 2.2.3)"],"_cs_severities":["high"],"_cs_tags":["cve-2025-50505","rce","privilege-escalation","clash-verge"],"_cs_type":"threat","_cs_vendors":["Clash Verge Rev"],"content_html":"\u003cp\u003eClash Verge Rev versions 2.2.3 and earlier contain an unauthenticated API endpoint at 127.0.0.1:33211/start_clash. The clash-verge-service, which typically operates with elevated system-level privileges (root or SYSTEM), fails to implement authentication for this interface. By sending a crafted JSON payload containing user-controlled parameters, including 'bin_path', 'config_dir', 'config_file', and 'log_file', an attacker can achieve arbitrary command execution on the host machine.\u003c/p\u003e\n\u003cp\u003eThe vulnerability is particularly critical because the service executes provided parameters as system commands. Attackers can exploit this locally for privilege escalation or remotely via DNS Rebinding attacks - leveraging the 0.0.0.0-day behavior in specific browsers - or by chaining the attack through an exposed local network proxy. Defenders should prioritize patching or restricting access to the local API service immediately, as functional proof-of-concept exploits are publicly available.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker hosts a malicious web page designed to perform DNS Rebinding or prepares a local script for LPE.\u003c/li\u003e\n\u003cli\u003eVictim machine accesses the malicious page or is targeted via a reachable local network proxy.\u003c/li\u003e\n\u003cli\u003eThe attacker issues a POST request to the local API endpoint at http://127.0.0.1:33211/start_clash.\u003c/li\u003e\n\u003cli\u003eThe request includes a JSON body with malicious parameters (e.g., 'bin_path' pointing to an attacker-controlled binary or script).\u003c/li\u003e\n\u003cli\u003eThe clash-verge-service receives the request and processes the 'bin_path' parameter without authentication or sanitization.\u003c/li\u003e\n\u003cli\u003eThe service executes the specified binary or script using the elevated privileges of the service process.\u003c/li\u003e\n\u003cli\u003eThe arbitrary command executes with root or SYSTEM-level permissions, completing privilege escalation or remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to execute arbitrary commands with the same privileges as the clash-verge-service (SYSTEM or root). This results in full system compromise, persistent unauthorized access, and potential data exfiltration. Given the nature of the application and the availability of exploitation vectors, unpatched instances are at high risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Clash Verge Rev to the latest patched version immediately to remediate CVE-2025-50505.\u003c/li\u003e\n\u003cli\u003eImplement host-based firewall rules to restrict access to the local loopback port 33211 to authorized processes only.\u003c/li\u003e\n\u003cli\u003eEnable browser protections that mitigate DNS Rebinding and Private Network Access (PNA) risks.\u003c/li\u003e\n\u003cli\u003eMonitor process creation logs for unexpected binaries or scripts being spawned by the 'clash-verge-service' process or related child processes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T06:12:28Z","date_published":"2026-09-14T06:12:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-50505/","summary":"Clash Verge Rev versions 2.2.3 and earlier are vulnerable to unauthenticated command execution via an API endpoint that can lead to local privilege escalation or remote code execution.","title":"Unauthenticated Command Execution in Clash Verge Rev","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-50505/"}],"language":"en","title":"CraftedSignal Threat Feed - Clash-Verge","version":"https://jsonfeed.org/version/1.1"}