CVE lookup
CVE-2026-52830
Pruva has a verified reproduction for CVE-2026-52830: fast-mcp-telegram <=0.19.0 allows bearer token path traversal to authenticate as the default telegram.session, bypassing reserved session name protections and enabling unauthorized access to Telegram MCP tools.. The canonical evidence record is REPRO-2026-00218.
REPRO
REPRO-2026-00218
Package
fast-mcp-telegram · pip
Severity
CRITICAL
Status
published