Junglewise Threat Intelligence

CVE-2026-76760: chenhg5 cc-connect unauthenticated RCE in webhook

CVE-2026-76760 · Severity: high · CVSS 7.3 · Published 2026-08-19

Technologies: Chenhg5 Cc-Connect. Vendors: Chenhg5.

Executive brief

cc-connect is a bridge tool that connects local AI coding agents to messaging platforms. The vulnerability allows attackers to execute arbitrary shell commands on servers running cc-connect without any authentication, by sending a simple HTTP request to the webhook endpoint. This can lead to complete system compromise, data theft, and ransomware deployment.

Technical details

The vulnerability is a code injection flaw (CWE-94) in the webhook authentication and command execution flow. The root cause consists of two chained issues: (1) the authenticate() function in core/webhook.go returns true when webhook.token is empty (the default configuration), intentionally disabling access control; (2) the handleHook() function passes user-controlled exec JSON fields directly to exec.CommandContext() in core/engine.go without sanitization. An unauthenticated remote attacker can POST arbitrary commands to the /hook endpoint, which are then executed on the server under the cc-connect process context. No authentication, special privileges, or user interaction is required. The exploit has been publicly disclosed with proof-of-concept code.

Affected products

  • chenhg5 cc-connect up to 1.4.1

Timeline

  • 2026-07-03: disclosed: Issue #1488 opened on GitHub with PoC
  • 2026-08-19: advisory: CVE-2026-76760 published

References

Related threats