Description
cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats, bypassing the per-user access controls that protect the text message handler.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized command via privileged card actions
Action: Immediate Patch
AI Analysis

Impact

cc-connect 1.5.0 fails to enforce a per‑user allowlist filter in the onCardAction handler that processes Feishu interactive card callbacks, allowing an attacker to trigger card actions within admitted chats and dispatch agent commands that normally require explicit user authorization, effectively bypassing the text message handler’s access controls.

Affected Systems

The vulnerability affects the cc‑connect application developed by chenhg5, specifically version 1.5.0; no other released versions are known to be affected.

Risk and Exploitability

The flaw carries a CVSS score of 8.7, indicating high severity because it permits privileged command execution. The EPSS score is below 1%, suggesting that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote via Feishu chat interactions, where an adversary who can send or trigger a card action in an admitted chat can bypass per‑user controls and execute unauthorized commands.

Generated by OpenCVE AI on September 18, 2026 at 00:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s official fix for cc‑connect 1.5.0 as soon as it becomes available
  • Disable or restrict Feishu interactive card callbacks until the patch is applied
  • Add custom per‑user allowlist checks in the onCardAction handler or enforce equivalent access controls

Generated by OpenCVE AI on September 18, 2026 at 00:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Chenhg5
Chenhg5 cc-connect
Vendors & Products Chenhg5
Chenhg5 cc-connect

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats, bypassing the per-user access controls that protect the text message handler.
Title cc-connect through 1.5.0 User Allowlist Bypass via Feishu Card Actions
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Chenhg5 Cc-connect
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T13:45:21.088Z

Reserved: 2026-09-16T19:47:13.501Z

Link: CVE-2026-92801

cve-icon Vulnrichment

Updated: 2026-09-17T13:45:16.527Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:29.680

Modified: 2026-09-23T17:17:48.320

Link: CVE-2026-92801

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:45:16Z

Weaknesses