PT-2026-99930 · Unknown · Fast-Mcp-Telegram
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
fast-mcp-telegram versions prior to 30.1
Description
The server is subject to a full-read, exfiltrating Server-Side Request Forgery (SSRF), a condition where an attacker can force the server to make requests to internal resources. The
send message and send message to phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to outgoing messages. While the validate url security function implements a denylist to check the literal hostname string, it does not resolve DNS. Since the actual fetch performed by httpx.AsyncClient.get resolves DNS at request time, a hostname resolving to a loopback, private, or link-local address can bypass the security guard. This allows an attacker to retrieve the body of the internal request as a Telegram file attachment, even when block private ips=True and allow http urls=False are configured.Recommendations
Update to version 30.1.
Exploit
Fix
Incomplete List of Disallowed Inputs
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fast-Mcp-Telegram