Server-Side Request Forgery in Telegram MCP Server by Fast-MCP
CVE-2026-55096

7.1HIGH

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-55096?

A vulnerability in the fast-mcp-telegram, before version 30.1, allows the send_message/send_message_to_phone MCP tools to process HTTP(s) URLs without proper DNS resolution. The _validate_url_security mechanism fails to guard against certain private address resolutions, enabling attackers to exploit the flaw. This results in the server fetching malicious content that can be returned as a Telegram file attachment, facilitating full read and data exfiltration capabilities.

Affected Version(s)

fast-mcp-telegram < 30.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.