{"id":"CVE-2026-92801","title":"cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks","summary":"cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats, bypassing the p…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-863"],"vendor":"chenhg5","product":"cc-connect","affected":["cc-connect <= 1.5.0"],"published":"2026-09-16","updated":"2026-09-17","sourceUpdated":"2026-09-17T14:17:56.463","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92801","references":[{"url":"https://github.com/chenhg5/cc-connect","label":"disclosure@vulncheck.com"},{"url":"https://github.com/chenhg5/cc-connect/blob/v1.5.0/platform/feishu/feishu.go#L661-L680","label":"disclosure@vulncheck.com"},{"url":"https://github.com/chenhg5/cc-connect/issues/1852","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/cc-connect-through-1.5.0-user-allowlist-bypass-via-feishu-card-actions","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-17T13:44:58.112417Z"},"ingestedAt":"2026-09-16T21:05:36.885Z","epss":0.00297,"epssPercentile":0.22597,"slug":"CVE-2026-92801","body":"## Overview\n\ncc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats, bypassing the per-user access controls that protect the text message handler.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}