Executive brief
WARP-Clash-API is a subscription management tool for handling API authentication across distributed configurations. A flaw in the subscription handler embeds sensitive API credentials directly in configuration files distributed to users, causing the master API key to persist in user configs, browser history, and server logs. An attacker who obtains a leaked key gains full account takeover and complete API access.
Technical details
The vulnerability is an improper access control flaw (CWE-284) in the get_surge_subscription function of services/subscription.py. The component embeds the raw SECRET_KEY as a query parameter (key=) in distributed Surge subscription .conf files, causing the master API credential to be exposed in plaintext to end users. The attack vector is network-based with no authentication required; any user who requests a Surge subscription receives the .conf file containing the embedded credentials. An attacker who obtains the leaked key from user-side config files, proxy logs, Referer headers, or browser history can gain full API account takeover. The product is on a rolling release basis with no official version numbering, and the vendor was unresponsive to early disclosure; the product is now archived and unsupported.
Affected products
- vvbbnn00 WARP-Clash-API up to commit c7bf2360073959861219b422e51ae86411051b46
Timeline
- 2026-07-18: disclosed
- 2026-09-13: advisory