CVE-2026-26422: Project Specific Clash Verge Insecure Ipc Check

The application utilizes client-side logic (`get_version` or `VERSION`) to determine service installation state, interacting with a known-vulnerable version of `clash_verge_service_ipc` (CVE-2026-26422). Under this design, the overly permissive IPC endpoint lacks server-side authorization boundaries. Upgrade to clash_verge_service_ipc >= 2.0.27 and use `clas

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Rust
greprules fetch cve-2026-26422-project-specific-clash-verge-insecure-ipc-check --engine opengrep

Description

The application utilizes client-side logic (`get_version` or `VERSION`) to determine service installation state, interacting with a known-vulnerable version of `clash_verge_service_ipc` (CVE-2026-26422). Under this design, the overly permissive IPC endpoint lacks server-side authorization boundaries. Upgrade to clash_verge_service_ipc >= 2.0.27 and use `clas