OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-55096

HIGH · CVSS 7.1 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The fast-mcp-telegram server prior to version 30.1 is vulnerable to a server-side request forgery (SSRF) attack due to improper validation of URLs in the send_message/send_message_to_phone MCP tools. This flaw allows an attacker to exploit the server to fetch files from internal or private network addresses, leading to potential data exfiltration through Telegram message attachments. Organizations using affected versions should prioritize patching to version 30.1 to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55096
Severity
HIGH
CVSS
7.1
EPSS
0.21%

Original NVD Description

fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's literal hostname string but never resolves DNS. The fetch (httpx.AsyncClient.get) does its own resolution at request time. Consequently a hostname that resolves to a loopback / private / link-local address passes the guard and is fetched — even with the secure defaults block_private_ips=True and allow_http_urls=False. Because the fetched body is returned to the attacker as a Telegram file attachment, this is a full-read, exfiltrating SSRF, not blind. This issue has been patched in version 30.1.