CVE-2026-92801 Details
Description
cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats, bypassing the per-user access controls that protect the text message handler.
A vulnerability exists in cc-connect versions through 1.5.0, where the application fails to properly enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. This oversight allows attackers to bypass access controls and dispatch agent commands by triggering card actions in chats where they are permitted.
Users can update to cc-connect version 1.5.1-beta.1 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 16, 2026CISA-ADP
Assessed Sep 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/chenhg5/cc-connect | [email protected] | ProductSource CodeVendor |
| https://github.com/chenhg5/cc-connect/blob/v1.5.0/platform/feishu/feishu.go#L661-L680 | [email protected] | Source CodeVendor |
| https://github.com/chenhg5/cc-connect/issues/1852 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/cc-connect-through-1.5.0-user-allowlist-bypass-via-feishu-card-actions | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| chenhg5 cc-connect | <= 1.5.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2026 | New CVE Received | [email protected] |
Volerion