User Allowlist Bypass Vulnerability in cc-connect by Chenhg5
CVE-2026-92801

8.7HIGH

Key Information:

Vendor

Chenhg5

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92801?

The cc-connect application, version 1.5.0, contains a vulnerability in its onCardAction handler that fails to enforce per-user allowlist filtering during Feishu interactive card callbacks. This weakness enables attackers to dispatch agent commands by triggering card actions in chats that are otherwise considered safe, effectively circumventing the intended per-user access controls. The vulnerability poses significant security risks by allowing unauthorized actions in permitted contexts, which could lead to further exploitation.

Affected Version(s)

cc-connect 0 <= 1.5.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.