CVE-2026-92801
—Authorization Bypass in cc-connect Feishu Card Action Handler
cc-connect through version 1.5.0 fails to apply per-user allowlist filtering in the onCardAction handler that processes Feishu (Lark) interactive card callbacks, even though the plain text message handler does enforce these access controls. An attacker who can trigger card actions inside a chat where the bot has been admitted can dispatch agent commands that the bot executes, bypassing the per-user access controls entirely. Because the dispatched commands run through the connected agent, the flaw carries high confidentiality, integrity, and availability impact (CVSS 4.0 score 8.7) while requiring only low privileges and no user interaction. Anyone running cc-connect 1.5.0 or earlier as a Feishu bot with interactive card callbacks enabled is affected. No public proof-of-concept is known and the flaw is not listed in CISA KEV, so exploitation is not currently known to be occurring.
What to do: Upgrade cc-connect to a release newer than 1.5.0 that enforces the per-user allowlist in the onCardAction handler as soon as a fixed version is available. As an interim mitigation, restrict or disable interactive card actions in admitted Feishu chats, and audit bot logs for agent commands triggered via card callbacks from users who are not on the allowlist.
| cc-connect (open-source project) cc-connect | all versions through 1.5.0 (≤ 1.5.0) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats, bypassing the per-user access controls that protect the text message handler.
- Weakness
- CWE-863
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.