User Allowlist Bypass Vulnerability in cc-connect by Chenhg5
CVE-2026-92801
8.7HIGH
What is CVE-2026-92801?
The cc-connect application, version 1.5.0, contains a vulnerability in its onCardAction handler that fails to enforce per-user allowlist filtering during Feishu interactive card callbacks. This weakness enables attackers to dispatch agent commands by triggering card actions in chats that are otherwise considered safe, effectively circumventing the intended per-user access controls. The vulnerability poses significant security risks by allowing unauthorized actions in permitted contexts, which could lead to further exploitation.
Affected Version(s)
cc-connect 0 <= 1.5.0
