在 vvbbnn00 WARP-Clash-API(截至提交 c7bf2360073959861219b422e51ae86411051b46)中发现了一个漏洞。受影响的组件是 函数。对参数 的不当处理会导致认证缺失。该攻击可远程发起。该漏洞的利用方法已公开披露,并可能已被利用。该产品采用持续交付和滚动发布机制,因此无法提供受影响版本及修复版本的详细版本信息。早在漏洞披露初期,维护者已被告知此事,但对方未作任何回应。此漏洞仅影响那些已不再由维护者支持的产品。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vvbbnn00 | WARP-Clash-API | c7bf2360073959861219b422e51ae86411051b46 |
cpe:2.3:a:vvbbnn00:warp-clash-api:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90507 | 6.3 MEDIUM | vvbbnn00 WARP-Clash-API Subscription subscription.py get_surge_subscription access control |
| CVE-2026-90506 | 5.0 MEDIUM | vvbbnn00 WARP-Clash-API Save Account Job race condition |
| CVE-2026-90505 | 5.0 MEDIUM | vvbbnn00 WARP-Clash-API doUpdateLicenseKey race condition |
No comments yet