CVE-2026-76761

medium

Description

A vulnerability was identified in chenhg5 cc-connect up to 1.4.1. This affects the function shellExecCommand of the file core/engine.go of the component Management API. Such manipulation of the argument exec leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The reported GitHub issue was closed automatically due to inactivity.

References

https://vuldb.com/vuln/393231/cti

https://vuldb.com/vuln/393231

https://vuldb.com/submit/878948

https://vuldb.com/cve/CVE-2026-76761

https://github.com/chenhg5/cc-connect/issues/1489

https://github.com/chenhg5/cc-connect/

Details

Source: Mitre, NVD

Published: 2026-08-19

Updated: 2026-08-20

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 7.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Severity: High

CVSS v4

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.01583