Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-108549: cc-connect up to 1.5.0 lets attackers send commands
CVE-2026-108549 · published today
Summary
The cc-connect software (versions up to 1.5.0) accepts messages on its webhook port without checking who sent them, if a secret key is not set. An attacker who can reach that port can pretend to be an authorized user and tell the server to run commands, such as a shell, on the host machine. Set a webhook secret or upgrade to a version that requires authentication to stop this risk.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| chenhg5 | cc-connect | <= 1.5.0 |
Original advisory text
cc-connect through 1.5.0 Missing Authentication via MAX Webhook Sender Spoofing
cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webhook listener on port 8080 can forge updates with an allowed or admin user_id to run privileged commands like /shell on the host.
References
- https://github.com/chenhg5/cc-connect product
- https://github.com/chenhg5/cc-connect/blob/v1.5.0/platform/max/max.go#L287-L305 technical-description
- https://github.com/chenhg5/cc-connect/issues/1968 issue-tracking
- https://www.vulncheck.com/advisories/cc-connect-through-1.5.0-missing-authentica... third-party-advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit (estimated)
- Gives an attacker full control (estimated)
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published10 Oct 2026
Updated10 Oct 2026
First seen10 Oct 2026
Track software like this
Free during beta