目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-52830— leshchenko1979 fast-mcp-telegram 路径遍历漏洞

CVSS 9.4 · Critical EPSS 0.55% · P42

影响版本矩阵 1

厂商产品版本范围状态
leshchenko1979fast-mcp-telegram< 0.19.1affected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-52830 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
来源: CVE Program / CVE List V5
Vulnerability Description
fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. The verifier rejects the exact reserved token telegram, but it does not reject path separators or normalize the path before checking whether the session file exists. A remote HTTP client can therefore authenticate as the default legacy session with a token such as ../fast-mcp-telegram/telegram when the documented default session file ~/.config/fast-mcp-telegram/telegram.session exists. This bypasses the reserved session name control that is intended to prevent HTTP multi-user sessions from colliding with the default stdio or legacy account. With account-prefixed MCP tools enabled, the attacker still sees and calls the prefixed tools for the default account, so the prefix middleware does not stop the session selection bypass. This vulnerability is fixed in 0.19.1.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
来源: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
来源: CVE Program / CVE List V5
Vulnerability Title
leshchenko1979 fast-mcp-telegram 路径遍历漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
leshchenko1979 fast-mcp-telegram是leshchenko1979个人开发者的一个Telegram消息代理组件。 leshchenko1979 fast-mcp-telegram 0.19.1之前版本存在安全漏洞,该漏洞源于验证HTTP Bearer令牌时未拒绝路径分隔符或规范化路径,可能导致远程HTTP客户端使用特制令牌绕过保留会话名称控制,以默认旧会话身份进行身份验证。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
leshchenko1979fast-mcp-telegram < 0.19.1 -

二、漏洞 CVE-2026-52830 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-52830 的情报信息

登录查看更多情报信息。

CVE-2026-52830 厂商安全公告 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-52830

暂无评论


发表评论