Server-Side Request Forgery in Telegram MCP Server by Fast-MCP
CVE-2026-55096
7.1HIGH
What is CVE-2026-55096?
A vulnerability in the fast-mcp-telegram, before version 30.1, allows the send_message/send_message_to_phone MCP tools to process HTTP(s) URLs without proper DNS resolution. The _validate_url_security mechanism fails to guard against certain private address resolutions, enabling attackers to exploit the flaw. This results in the server fetching malicious content that can be returned as a Telegram file attachment, facilitating full read and data exfiltration capabilities.
Affected Version(s)
fast-mcp-telegram < 30.1
