CVE-2026-92801

Summary

cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats, bypassing the per-user access controls that protect the text message handler.

Affected Software

VendorProductVersion RangeStatus
chenhg5cc-connect0 <= 1.5.0affected

Weaknesses

  • CWE-863: Incorrect Authorization

References