CVE-2025-50505

HIGH

Clash Verge Rev <2.3.0 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2025-50505. PoCs published by a0yami, bron1e.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2025-50505, an unauthenticated API vulnerability in Clash Verge Rev that allows arbitrary command execution and privilege escalation. It includes exploitation vectors for both local privilege escalation and remote code execution via LAN or DNS rebinding attacks.

Description

Clash Verge Rev thru 2.2.3 (fixed in 2.3.0) forces the installation of system services(clash-verge-service) by default and exposes key functions through the unauthorized HTTP API `/start_clash`, allowing local users to submit arbitrary bin_path parameters and pass them directly to the service process for execution, resulting in local privilege escalation.

Exploits (2)

nomisec WRITEUP 15 stars
by a0yami · poc
https://github.com/a0yami/CVE-2025-50505

This repository provides a detailed technical analysis of CVE-2025-50505, an unauthenticated API vulnerability in Clash Verge Rev that allows arbitrary command execution and privilege escalation. It includes exploitation vectors for both local privilege escalation and remote code execution via LAN or DNS rebinding attacks.

Classification
Writeup 100%
Attack Type
Rce | Lpe
Complexity
Moderate
Reliability
Reliable
Target: Clash Verge Rev <= v2.2.3
No auth needed
Prerequisites: Clash Verge Rev installed with elevated privileges · LAN access or DNS rebinding setup for RCE
devstral-2 · analyzed Mar 23, 2026 Full analysis →
nomisec WRITEUP 15 stars
by bron1e · poc
https://github.com/bron1e/CVE-2025-50505

This repository provides a detailed technical analysis of CVE-2025-50505, an unauthenticated API vulnerability in Clash Verge Rev that allows arbitrary command execution and privilege escalation. It includes root cause analysis, vulnerable code snippets, and exploitation vectors for both local and remote scenarios.

Classification
Writeup 100%
Attack Type
Rce | Lpe
Complexity
Moderate
Reliability
Reliable
Target: Clash Verge Rev <= v2.2.3
No auth needed
Prerequisites: Clash Verge Rev installed with elevated privileges · LAN access or DNS rebinding setup for RCE
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0021
EPSS Percentile 11.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-250
Status published
Published Oct 07, 2025
Tracked Since Feb 18, 2026