logo

Critical fast-mcp-telegram Vulnerability Lets Attackers Access Telegram Session Without Token

ID: 5573fb17-9555-5e31-ba90-ec76b26908be

STIX ID: report--5573fb17-9555-5e31-ba90-ec76b26908be

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-07-06

Date Updated: 2026-07-21

Author: Divya

...
...

**Critical fast-mcp-telegram Vulnerability (CVE-2026-52830):** A path‑traversal weakness in session-file token handling allows an attacker to supply a crafted bearer token (for example a relative path like ../fast-mcp-telegram/telegram) that resolves to the default telegram.session, bypassing the intended high‑entropy token boundary and granting full read/write and MTProto access to the default Telegram account; affects fast-mcp-telegram ≤ 0.19.0 and is fixed by stricter token validation in 0.19.1 — immediate remediation includes upgrading, rotating legacy/default sessions, rejecting path separators/traversal sequences, and verifying resolved session paths remain under the configured session directory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.