PT-2026-99930 · Unknown · Fast-Mcp-Telegram

·

CVE-2026-55096

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions fast-mcp-telegram versions prior to 30.1
Description The server is subject to a full-read, exfiltrating Server-Side Request Forgery (SSRF), a condition where an attacker can force the server to make requests to internal resources. The send message and send message to phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to outgoing messages. While the validate url security function implements a denylist to check the literal hostname string, it does not resolve DNS. Since the actual fetch performed by httpx.AsyncClient.get resolves DNS at request time, a hostname resolving to a loopback, private, or link-local address can bypass the security guard. This allows an attacker to retrieve the body of the internal request as a Telegram file attachment, even when block private ips=True and allow http urls=False are configured.
Recommendations Update to version 30.1.

Exploit

Fix

Incomplete List of Disallowed Inputs

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55096
GHSA-XR72-J7VJ-VP7G

Affected Products

Fast-Mcp-Telegram