logo

Fast-mcp-telegram Vulnerability Allow Attackers to Access Sensitive Files

ID: 643a0d58-fc96-5b73-8c56-3b83295feccd

STIX ID: report--643a0d58-fc96-5b73-8c56-3b83295feccd

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-07-07

Date Updated: 2026-07-07

Author: Abinaya

...
...

A path-traversal vulnerability (CVE-2026-52830) in fast-mcp-telegram (≤0.19.0) allows attackers to craft bearer tokens (e.g., "../fast-mcp-telegram/telegram") that bypass authentication and access the default Telegram session file, potentially enabling reading and sending messages and other account actions; maintainers released version 0.19.1 to fix the issue and users should upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.