Impact
cc-connect 1.5.0 fails to enforce a per‑user allowlist filter in the onCardAction handler that processes Feishu interactive card callbacks, allowing an attacker to trigger card actions within admitted chats and dispatch agent commands that normally require explicit user authorization, effectively bypassing the text message handler’s access controls.
Affected Systems
The vulnerability affects the cc‑connect application developed by chenhg5, specifically version 1.5.0; no other released versions are known to be affected.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating high severity because it permits privileged command execution. The EPSS score is below 1%, suggesting that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote via Feishu chat interactions, where an adversary who can send or trigger a card action in an admitted chat can bypass per‑user controls and execute unauthorized commands.
OpenCVE Enrichment