CVE-2026-92801: CHENHG5 Cc-Connect

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats, bypassing the per-user access controls that protect the text message handler.

Affected products

  • CHENHG5 Cc-Connect: up to and including 1.5.0

Published 2026-09-16. Last modified 2026-09-23.