Skip to content

CVE lookup

CVE-2026-52830

Pruva has a verified reproduction for CVE-2026-52830: fast-mcp-telegram <=0.19.0 allows bearer token path traversal to authenticate as the default telegram.session, bypassing reserved session name protections and enabling unauthorized access to Telegram MCP tools.. The canonical evidence record is REPRO-2026-00218.

REPRO

REPRO-2026-00218

Package

fast-mcp-telegram · pip

Severity

CRITICAL

Status

published