Impact
The vulnerability is a race condition in the Save Account Job function of vvbbnn00 WARP‑Clash‑API. Remote attackers can trigger a timing mismatch that may lead to inconsistent or corrupted account data. The flaw requires high attack complexity and is considered difficult to exploit, yet it has been publicly disclosed and could be used if an opportunity arises.
Affected Systems
vvbbnn00 WARP‑Clash‑API is affected, with the issue present in releases up to commit c7bf2360073959861219b422e51ae86411051b46. Because the product follows a rolling-release model, specific version details are not listed, and the flaw only impacts releases that are no longer supported by the maintainer.
Risk and Exploitability
3 the severity is low, the EPSS score is < 1%, indicating a very low probability of exploitation. The attack vector is remote, requiring high complexity and difficult exploitability. Even though the risk is low, the public disclosure means the vulnerability could still be exploited against unsupported installations.
OpenCVE Enrichment