Description
fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's literal hostname string but never resolves DNS. The fetch (httpx.AsyncClient.get) does its own resolution at request time. Consequently a hostname that resolves to a loopback / private / link-local address passes the guard and is fetched — even with the secure defaults block_private_ips=True and allow_http_urls=False. Because the fetched body is returned to the attacker as a Telegram file attachment, this is a full-read, exfiltrating SSRF, not blind. This issue has been patched in version 30.1.
Published: 2026-09-28
Score: 7.1 High
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Leshchenko1979
Leshchenko1979 fast-mcp-telegram
Vendors & Products Leshchenko1979
Leshchenko1979 fast-mcp-telegram

Mon, 28 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's literal hostname string but never resolves DNS. The fetch (httpx.AsyncClient.get) does its own resolution at request time. Consequently a hostname that resolves to a loopback / private / link-local address passes the guard and is fetched — even with the secure defaults block_private_ips=True and allow_http_urls=False. Because the fetched body is returned to the attacker as a Telegram file attachment, this is a full-read, exfiltrating SSRF, not blind. This issue has been patched in version 30.1.
Title SSRF via DNS-resolution gap in _validate_url_security (file download by URL)
Weaknesses CWE-184
CWE-918
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Leshchenko1979 Fast-mcp-telegram
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-28T16:38:26.730Z

Reserved: 2026-06-16T14:41:54.578Z

Link: CVE-2026-55096

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T17:17:50.007

Modified: 2026-09-28T17:17:50.007

Link: CVE-2026-55096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:15:05Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs

  • CWE-918

    Server-Side Request Forgery (SSRF)