Impact
The vulnerability resides in the get_surge_subscription function of services/subscription.py within the Subscription Handler component of the vvbbnn00 WARP-Clash-API. By manipulating the argument key, an attacker can bypass proper authentication checks and gain unauthorized access to surge subscription data. The weakness originates from improper handling of input authentication and lack of authorization safeguards, as identified by CWE‑266 and CWE‑284.
Affected Systems
The issue impacts the vvbbnn00 WARP-Clash-API product, up to commit c7bf2360073959861219b422e51ae86411051b46. Because the project follows a rolling‑release schedule and the vendor has ceased maintenance for the affected build, specific version numbers are not listed. The Subscription Handler module in services/subscription.py is the exposed component.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of widespread exploitation. However, the vulnerability is publicly documented and the product is no longer supported, which makes any existing deployment at risk for remote attacks targeting the vulnerable endpoint. The lack of official patches or workarounds further raises the overall risk for organizations still operating this API.
OpenCVE Enrichment