vvbbnn00 开发的 WARP-Clash-API(版本标识为 c7bf2360073959861219b422e51ae86411051b46 及之前版本)中存在一个漏洞,受影响的功能为 。该漏洞源于竞态条件(race condition),攻击者可远程发起攻击,但攻击复杂度较高。可利用性被评估为“困难”(difficult)。相关利用代码/技术已公开,可能被用于实际利用。该产品不使用传统的版本号管理,因此无法提供具体受影响或未受影响的版本信息。维护方虽在披露初期即被联系,但始终未作出任何回应。此外,该漏洞仅
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vvbbnn00 | WARP-Clash-API | c7bf2360073959861219b422e51ae86411051b46 |
cpe:2.3:a:vvbbnn00:warp-clash-api:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90504 | 7.3 HIGH | vvbbnn00 WARP-Clash-API authorized missing authentication |
| CVE-2026-90507 | 6.3 MEDIUM | vvbbnn00 WARP-Clash-API Subscription subscription.py get_surge_subscription access control |
| CVE-2026-90506 | 5.0 MEDIUM | vvbbnn00 WARP-Clash-API Save Account Job race condition |
No comments yet