vvbbnn00 的 WARP-Clash-API 组件中存在一个已确认的漏洞,影响版本范围为 c7bf2360073959861219b422e51ae86411051b46。该漏洞位于“Save Account Job”组件中的某个未知函数中。通过操纵该函数会引发竞态条件(race condition)。该攻击可远程发起,但攻击复杂度被评为高,且利用难度较高。该漏洞的利用方式已被公开披露,并可能已被利用。该产品采用滚动发布模式以提供持续更新,因此受影响版本或修复版本的具体版本信息不可用。厂商曾就本次披露事宜提前
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vvbbnn00 | WARP-Clash-API | c7bf2360073959861219b422e51ae86411051b46 |
cpe:2.3:a:vvbbnn00:warp-clash-api:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90504 | 7.3 HIGH | vvbbnn00 WARP-Clash-API authorized missing authentication |
| CVE-2026-90507 | 6.3 MEDIUM | vvbbnn00 WARP-Clash-API Subscription subscription.py get_surge_subscription access control |
| CVE-2026-90505 | 5.0 MEDIUM | vvbbnn00 WARP-Clash-API doUpdateLicenseKey race condition |
No comments yet