Junglewise Threat Intelligence

CVE-2026-76761: chenhg5 cc-connect OS command injection in Management API

CVE-2026-76761 · Severity: high · CVSS 7.3 · Published 2026-08-19

Technologies: Chenhg5 Cc-Connect. Vendors: Chenhg5.

Executive brief

cc-connect is a bridge application that connects local AI coding agents to messaging platforms. The Management API contains an authentication bypass combined with OS command injection that allows unauthenticated attackers to execute arbitrary commands on the server by creating malicious cron jobs. This enables full server compromise, data theft, and lateral movement into internal networks.

Technical details

The vulnerability is a chained authentication bypass (CWE-306) and OS command injection (CWE-78) in the Management API. The authenticate() function returns true when management.token is empty (the default configuration), bypassing all authentication checks. Unauthenticated attackers can POST to /api/v1/cron to create cron jobs with user-controlled exec parameters that are executed as shell commands via shellExecCommand() in core/engine.go. Attack vector is network-based with no authentication or user interaction required. Successful exploitation grants arbitrary command execution with the privileges of the cc-connect process. The issue is publicly disclosed with working proof-of-concept code available.

Affected products

  • chenhg5 cc-connect up to 1.4.1

Timeline

  • 2026-07-03: disclosed: GitHub issue #1489 opened with full vulnerability disclosure
  • 2026-08-19: disclosed: CVE-2026-76761 published

References

Related threats