Impact
A code injection vulnerability in chenhg5:cc-connect allows an attacker to manipulate the exec argument of the Authenticate function in core/webhook.go, resulting in arbitrary code execution on the host system that runs the webhook service. The injection can be triggered from a remote caller, providing the ability to execute arbitrary commands.
Affected Systems
Versions of chenhg5:cc-connect up to and including 1.4.1 are affected. The vulnerability exists in the Authenticate function used by webhook endpoints and is present in all installations of the listed package prior to the latest revision. All instances that have not been updated beyond 1.4.1 remain vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity. No EPSS score is currently available, and the issue has not been listed in the CISA KEV catalog, but a publicly available exploit demonstrates that remote attackers can craft a request to the webhook to gain code execution. The remote nature of the attack and the lack of any effective mitigation means the risk is significant and exploitation is feasible in a realistic threat model.
OpenCVE Enrichment