Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

fast-mcp-telegram MCP server auth bypass via path traversal in bearer token (CVE-2026-52830)

Versions of the fast-mcp-telegram Telegram MCP server prior to 0.19.1 built session-file paths directly from HTTP Bearer tokens without normalising path separators, letting a remote client authenticate as the default legacy Telegram session using a token such as '../fast-mcp-telegram/telegram'. The flaw bypassed the reserved session-name control and was fixed in release 0.19.1.

Disclosed 2 July 2026 · Record updated 13 September 2026

Impact

A remote HTTP client could select and operate the default/legacy Telegram account session on the MCP server, including calling account-prefixed MCP tools for that account.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-52830