New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Bug]: Remote Code Execution/远程代码执行 #2710
Comments
我已经向作者的iCloud邮箱发送了一封带了PoC的邮件 |
非常感谢,下个版本修复 |
fixed or implement in latest release, check it out from https://github.com/Fndroid/clash_for_windows_pkg/releases |
okay, I'll make it public now |
@Anthem-whisper 低于0.19.8是否受到影响? |
Electron框架写代码不开沙盒的屑 (doge |
|
围观 |
锤子 低版本都受影响 机场直接变鸡场 乱杀 我查毒去了... |
吃瓜群众 |
right |
这xss和开不开沙盒有关么你看来,不开沙盒就是垃圾是吗? |
我给维护者 @Fndroid 的iCloud邮箱发了邮件,我希望能在GitHub仓库发布安全通告 |
https://www.electronjs.org/zh/docs/latest/tutorial/sandbox
|
测试了0.14和0.18都受到影响,有没有强制更新措施啊 |
0.18.8也可以复现 |
谢谢楼主 |
0.19.2也可以( |
希望可以发布一个影响范围(版本号范围?)的说明 |
poc里面不是说了吗,小于等于0.19.8都受影响 |
更新至0.19.10,测试不受影响 |
感谢 |
更正一下,0.19.9版本并没有完全修复,请更新到0.19.10 |
感谢,已升级最新版 |
在现场,贴贴 |
还好我情报工作OK |
感谢,已升级最新版,贴贴 |
还在使用 0.11.3 版本 :) |
0.19.11 |
Clash For Windows Remote Code Execution
Description
Clash For Windows is powered by Electron. If a XSS payload is in the name of proxies, we can remotely execute any JavaScript code on the victim's computer.
Affected versions of clash_for_windows_pkg
version: 0.19.8 (there are other vulnerability triggers in version 0.19.9, it's exactly 0.19.9)
Platform: Windows
OS specifics: Windows 10
PoC
Switch to it in "Profiles"
Click "Proxies" column (Sometimes it's not necessary.)
Attention:
A way to Exploit
put the evil config file to internets and use
clash://
to install it, clash_for_windows_pkg will download and switch to it automaticlly .such as:
The text was updated successfully, but these errors were encountered: