Fast-mcp-telegram Vulnerability Allow Attackers to Access Sensitive Files
ID: 643a0d58-fc96-5b73-8c56-3b83295feccd
STIX ID: report--643a0d58-fc96-5b73-8c56-3b83295feccd
Feed Name: cybersecurityNews.com
Threat Score
A path-traversal vulnerability (CVE-2026-52830) in fast-mcp-telegram (≤0.19.0) allows attackers to craft bearer tokens (e.g., "../fast-mcp-telegram/telegram") that bypass authentication and access the default Telegram session file, potentially enabling reading and sending messages and other account actions; maintainers released version 0.19.1 to fix the issue and users should upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
