{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/chenhg5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-76760"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cc-connect (1.4.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","injection","web-application"],"_cs_type":"advisory","_cs_vendors":["chenhg5"],"content_html":"\u003cp\u003eA code injection vulnerability has been identified in chenhg5 cc-connect, affecting all versions up to and including 1.4.1. The vulnerability resides within the 'Authenticate' function located in 'core/webhook.go'. The application fails to properly neutralize user-controlled input passed to the 'exec' argument, allowing an unauthenticated remote attacker to inject and execute arbitrary code. The exploit for this vulnerability is currently public, increasing the risk of exploitation by threat actors targeting this service. Defenders should prioritize patching or restricting access to the affected webhook endpoint to prevent exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthenticated remote code execution on the server hosting the cc-connect service. This grants an attacker the ability to execute arbitrary commands, potentially leading to full system compromise, data exfiltration, or deployment of additional malicious payloads.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade chenhg5 cc-connect to a patched version beyond 1.4.1 immediately.\u003c/li\u003e\n\u003cli\u003eIf patching is not feasible, implement strict input validation or block access to the 'core/webhook.go' endpoint at the web application firewall (WAF) or ingress proxy level, specifically monitoring for the 'exec' argument containing shell metacharacters.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous requests to webhook endpoints involving the 'exec' parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-20T00:39:47Z","date_published":"2026-08-20T00:39:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cc-connect-injection/","summary":"An unauthenticated remote code injection vulnerability in the Authenticate function of chenhg5 cc-connect (up to 1.4.1) allows attackers to execute arbitrary code via the exec parameter.","title":"Remote Code Injection in chenhg5 cc-connect","url":"https://feed.craftedsignal.io/briefs/2026-08-cc-connect-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Chenhg5","version":"https://jsonfeed.org/version/1.1"}