PT-2026-94075 · Chenhg5+1 · Cc-Connect
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
cc-connect versions prior to 1.5.1
Description
The software fails to enforce per-user allowlist filtering within the
onCardAction handler used for Feishu interactive card callbacks. This flaw allows attackers to dispatch agent commands by triggering card actions in admitted chats, effectively bypassing the per-user access controls that normally protect the text message handler.Recommendations
Update cc-connect to version 1.5.1 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cc-Connect