All 4 CVE vulnerabilities found in cc-connect, with AI-generated Chinese analysis, references, and POCs.
Vendor: chenhg5
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-108549 | cc-connect through 1.5.0 Missing Authentication via MAX Webhook Sender Spoofing CWE-306 | 8.1 | High | 2026-10-10 |
| CVE-2026-92801 | cc-connect through 1.5.0 User Allowlist Bypass via Feishu Card Actions CWE-863 | 8.8 | High | 2026-09-16 |
| CVE-2026-76761 | chenhg5 cc-connect Management API engine.go shellExecCommand os command injection CWE-78 | 7.3 | High | 2026-08-19 |
| CVE-2026-76760 | chenhg5 cc-connect webhook.go authenticate code injection CWE-94 | 7.3 | High | 2026-08-19 |
All 4 known CVE vulnerabilities affecting cc-connect with full Chinese analysis, references, and POCs where available.