CVE-2026-52830Disclosure

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. The verifier rejects the exact reserved token telegram, but it does not reject path separators or normalize the path before checking whether the session file exists. A remote HTTP client can therefore authenticate as the default legacy session with a token such as ../fast-mcp-telegram/telegram when the documented default session file ~/.config/fast-mcp-telegram/telegram.session exists. This bypasses the reserved session name control that is intended to prevent HTTP multi-user sessions from colliding with the default stdio or legacy account. With account-prefixed MCP tools enabled, the attacker still sees and calls the prefixed tools for the default account, so the prefix middleware does not stop the session selection bypass. This vulnerability is fixed in 0.19.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-07-02); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-02: 2Mentions · 2026-07-03: 1Mentions · 2026-07-14: 1Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-02: 2Technical Details · 2026-07-03: 1Technical Details · 2026-07-14: 107-0207-0307-14
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-022
Disclosure2
2026-07-031
Disclosure1
2026-07-141
Disclosure1
Full discourse4 posts
  • iototsecnews@iototsecnews
    Disclosure

    fast-mcp-telegram の認証バイパス脆弱性 CVE-2026-52830:認証の不備と機密ファイル・アクセスの恐れ https://iototsecnews.jp/2026/07/06/fast-mcp-telegram-vulnerability-allow-attackers-to-access-sensitive-files/ 今回の問題の原因は、認証に使用される HTTP Bearer トークンの検証が不適切だったことにあります。 fast-mcp-telegram というパッケージにおいて、ユーザーから入力されたトークンが、セッション・ファイルのパス構築に直接使用されていました。プログラム側において、特定のセッション名をブロックする仕組みがありますが、入力のサニタイズや正規化が不十分なことで、パス・トラバーサル手法による制限の回避を許してしまいました。具体的には、 “/” や “..” といった文字列が制限されておらず、解決後のファイルパスが意図したディレクトリ内に収まっているかの検証も行われていませんでした。この入力検証の不備とパス・トラバーサルの欠陥が組み合わさった結果として、認証がバイパスされる脆弱性 CVE-2026-52830 が発生しました。ご利用のチームは、ご注意ください。 #CVE202652830 #fastmcptelegram #Vulnerability

    Post summary

    The article announces CVE-2026-52830, an authentication bypass caused by inadequate token validation and path traversal, highlighting the risk of unauthorized file access.

    01000218
    502 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - fast-mcp-telegram Bearer-Token Path Traversal Auth Bypass (CVE-2026-52830) fast-mcp-telegram's HTTP auth joins the raw bearer token into a session-file path without rejecting path separators or normalizing it. It blocks the exact reserved token "telegram", but a traversal token like ../fast-mcp-telegram/telegram resolves back to the default ~/.config/fast-mcp-telegram/telegram.session and is accepted. An unauthenticated remote client with no valid generated token can thereby authenticate as the default/legacy Telegram session and call its MCP tools - reading and sending messages, MTProto API calls, and attachment surfaces. The account-prefix middleware is downstream of auth and cannot recover the boundary. 👉Upgrade fast-mcp-telegram to 0.19.1.

    Post summary

    Fast‑mcp‑telegram has a path‑traversal authentication bypass (CVE‑2026‑52830) that lets attackers impersonate the default Telegram session; upgrading to version 0.19.1 resolves the issue.

    0000085
    236 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-52830 fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. … https://www.cve.org/CVERecord?id=CVE-2026-52830 ----- Traducción: CVE-2026-52830 fas… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑52830, describing a token validation flaw in fast‑mcp‑telegram that may allow path traversal, and notes that the issue existed before version 0.19.1, implying a patch.

    0000050
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-52830 fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. … https://www.cve.org/CVERecord?id=CVE-2026-52830

    Post summary

    The tweet announces CVE-2026-52830, detailing a path‑based token validation flaw in fast-mcp‑telegram, but supplies no exploit, patch, or active usage information.

    00000700
    57.7K followersView on X

Explore more