CVE-2026-55096 Details
Description
fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's literal hostname string but never resolves DNS. The fetch (httpx.AsyncClient.get) does its own resolution at request time. Consequently a hostname that resolves to a loopback / private / link-local address passes the guard and is fetched — even with the secure defaults block_private_ips=True and allow_http_urls=False. Because the fetched body is returned to the attacker as a Telegram file attachment, this is a full-read, exfiltrating SSRF, not blind. This issue has been patched in version 30.1.
A server-side request forgery (SSRF) vulnerability has been identified in fast-mcp-telegram, a Telegram MCP server, in versions prior to 30.1. The issue arises in the send_message and send_message_to_phone MCP tools, which allow files to be sent as a list of HTTP or HTTPS URLs. The server downloads these files and attaches them to the outgoing Telegram messages. The download process is supposed to be secured by a URL validation function that checks the hostname against a denylist to block loopback, private, and link-local addresses. However, this validation only checks the hostname string without resolving the DNS, allowing malicious URLs that point to internal services to bypass the security and be fetched by the server. This vulnerability has been patched in version 30.1.
Users can update to fast-mcp-telegram version 30.1 or later, where this vulnerability has been fixed. The patch involves resolving DNS before validating URLs to prevent SSRF attacks by blocking access to loopback, private, and link-local addresses.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/leshchenko1979/fast-mcp-telegram/commit/e6b3032cfc906e14f5b84f2c2b8ec378eb457e57 | [email protected] | Source CodeVendor |
| https://github.com/leshchenko1979/fast-mcp-telegram/releases/tag/0.30.1 | [email protected] | Release NotesVendor |
| https://github.com/leshchenko1979/fast-mcp-telegram/security/advisories/GHSA-xr72-j7vj-vp7g | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-184 | Incomplete List of Disallowed Inputs | [email protected] |
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| leshchenko1979 fast-mcp-telegram | <= 0.30.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion