Junglewise Threat Intelligence

CVE-2026-52830: leshchenko1979 fast-mcp-telegram authentication bypass via path traversal

CVE-2026-52830 · Severity: critical · CVSS 9.4 · Published 2026-07-02

Vendors: PyPI.

Executive brief

fast-mcp-telegram is a server that allows AI models and other tools to interact with Telegram accounts. A security flaw allows unauthorized individuals to bypass authentication and take control of the default Telegram account connected to the server. An attacker could read private messages, send messages as the user, and access sensitive account data without needing a valid password or token.

Technical details

A path traversal vulnerability exists in the SessionFileTokenVerifier.verify_token() method of fast-mcp-telegram. The application attempts to block a reserved 'telegram' session name but fails to normalize the input token before appending a '.session' extension and checking for file existence. An unauthenticated remote attacker can provide a crafted Bearer token containing path traversal sequences (e.g., '../fast-mcp-telegram/telegram') to resolve to the default legacy session file. This allows the attacker to authenticate as the default account and execute MCP tools, including reading and sending messages via the MTProto API. The issue is resolved in version 0.19.1 by implementing strict token validation.

Affected products

  • leshchenko1979 fast-mcp-telegram < 0.19.1

Timeline

  • 2026-05-29: disclosed: Advisory published on GitHub
  • 2026-07-02: advisory: NVD publication date
  • 2026-07-02: patched: Fix confirmed in version 0.19.1

References