Subcategory

Observability

Coverage of open AI infrastructure, repos, runtimes, and the control layers forming around them. Filtered by Observability.

1 story

Critical Path-Traversal Vulnerability Patched in Telegram MCP Package

Critical Path-Traversal Vulnerability Patched in Telegram MCP Package

A critical security vulnerability tracked as CVE-2026-52830 was disclosed and patched in the fast-mcp-telegram package, affecting all versions up to 0.19.0. The flaw stems from improper validation of HTTP Bearer tokens, which are used directly to construct file paths to session files on disk. Attackers can exploit this path-traversal vulnerability using a crafted token to bypass authentication and gain full message and MTProto access to the default Telegram session.

  • #GitHub Trending
4 min read