URL has been copied successfully!
Critical fast-mcp-telegram Vulnerability Lets Attackers Access Telegram Session Without Token
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Critical fast-mcp-telegram Vulnerability Lets Attackers Access Telegram Session Without Token

A critical vulnerability in fast-mcp-telegram (CVE-2026-52830, GHSA-rxw2-pc8j-vxwm) allows attackers to access a Telegram MCP session over HTTP without a valid bearer token by abusing a path-traversal flaw in how session files are resolved on disk. This breaks the intended high-entropy token boundary and exposes the default Telegram account to full message and MTProto access. Critical […] The post Critical fast-mcp-telegram Vulnerability Lets Attackers Access Telegram Session Without Token appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

First seen on gbhackers.com

Jump to article: gbhackers.com/critical-fast-mcp-telegram-vulnerability/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link