CVE-2025-50505
7.8Clash Verge Rev · Clash Verge Rev
Clash Verge Rev versions through 2.2.3 contain a local privilege escalation vulnerability via an unauthorized HTTP API, allowing local users to execute arbitrary commands with elevated privileges.
Executive summary
Clash Verge Rev versions through 2.2.3 are vulnerable to local privilege escalation, which allows a local attacker to execute arbitrary binaries with system service permissions.
Vulnerability
The application forces the installation of a system service and exposes an unauthorized HTTP API endpoint, /start_clash, which accepts an arbitrary bin_path parameter that is executed directly by the service process. This flaw allows a local user with low privileges to escalate their access to the system service level.
Business impact
Successful exploitation of this vulnerability results in full local privilege escalation, granting an attacker administrative control over the affected system. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to complete system compromise, unauthorized data access, and the ability to install persistent malware or backdoors on the host.
Remediation
Immediate Action: Update Clash Verge Rev to version 2.3.0 or later to patch the vulnerable API and secure the service communication.
Proactive Monitoring: Monitor system logs for unauthorized service execution or unexpected calls to the Clash Verge service process.
Compensating Controls: Restrict local user access to the system and ensure that only authorized users have the capability to interact with local HTTP APIs or service configurations.
Exploitation status
Public Exploit Available: Yes — a public proof-of-concept exists as documented in the research repository at github.com/bron1e/CVE-2025-50505.
Analyst recommendation
The risk posed by CVE-2025-50505 is significant for any environment utilizing Clash Verge Rev. Organizations must prioritize the update to version 2.3.0 to neutralize the privilege escalation vector. Failure to patch allows any local user to gain unauthorized control over the service, which may facilitate further lateral movement or system-wide disruption.