CVE-2026-76760

Source
https://cve.org/CVERecord?id=CVE-2026-76760
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76760.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-76760
Published
2026-08-19T22:45:14Z
Modified
2026-08-22T03:31:13Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
chenhg5 cc-connect webhook.go authenticate code injection
Details

A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vulnerability is the function Authenticate of the file core/webhook.go. The manipulation of the argument exec results in code injection. The attack may be performed from remote. The exploit has been made public and could be used. The reported GitHub issue was closed automatically due to inactivity.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-74",
        "CWE-94"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76760.json"
}
References

Affected packages

Git / github.com/chenhg5/cc-connect

Affected ranges

Type
GIT
Repo
https://github.com/chenhg5/cc-connect
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.4.0"
        },
        {
            "last_affected": "1.4.0"
        },
        {
            "introduced": "1.4.1"
        },
        {
            "last_affected": "1.4.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.4.0
1.4.1
v1.*
v1.4.0
v1.4.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76760.json"