VYPR
Vendor

Chenhg5

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-92801HigSep 16, 2026
    risk 0.50cvss 8.8epss 0.00

    cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats, bypassing the per-user access controls that protect the…

  • CVE-2026-76761HigAug 19, 2026
    risk 0.48cvss 7.3epss 0.02

    A vulnerability was identified in chenhg5 cc-connect up to 1.4.1. This affects the function shellExecCommand of the file core/engine.go of the component Management API. Such manipulation of the argument exec leads to os command injection. It is possible to launch the attack…

  • CVE-2026-76760HigAug 19, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vulnerability is the function Authenticate of the file core/webhook.go. The manipulation of the argument exec results in code injection. The attack may be performed from remote. The exploit has been…