CVE-2025-50505

HIGH

Clash Verge Rev <2.3.0 - Privilege Escalation

Title source: llm

Description

Clash Verge Rev thru 2.2.3 (fixed in 2.3.0) forces the installation of system services(clash-verge-service) by default and exposes key functions through the unauthorized HTTP API `/start_clash`, allowing local users to submit arbitrary bin_path parameters and pass them directly to the service process for execution, resulting in local privilege escalation.

Exploits (2)

nomisec WRITEUP 15 stars
by a0yami · poc
https://github.com/a0yami/CVE-2025-50505
nomisec WRITEUP 15 stars
by bron1e · poc
https://github.com/bron1e/CVE-2025-50505

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 6.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-250
Status published
Published Oct 07, 2025
Tracked Since Feb 18, 2026