在 vvbbnn00 WARP-Clash-API 项目中(版本范围直至 c7bf2360073959861219b422e51ae86411051b46)发现了一个漏洞。受影响的是组件 Subscription Handler 中文件 services/subscription.py 里的函数 get_surge_subscription。对参数 key 的不当操控会导致访问控制不当。该攻击可能由远程发起。利用该漏洞的代码已公开,因此可能被使用。该产品采用滚动发布机制,确保持续交付,因此受影响版本和更新版本均无具
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vvbbnn00 | WARP-Clash-API | c7bf2360073959861219b422e51ae86411051b46 |
cpe:2.3:a:vvbbnn00:warp-clash-api:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90504 | 7.3 HIGH | vvbbnn00 WARP-Clash-API authorized missing authentication |
| CVE-2026-90506 | 5.0 MEDIUM | vvbbnn00 WARP-Clash-API Save Account Job race condition |
| CVE-2026-90505 | 5.0 MEDIUM | vvbbnn00 WARP-Clash-API doUpdateLicenseKey race condition |
No comments yet