---
id: CVE-2026-55096
title: fast-mcp-telegram is a Telegram MCP Server
summary: >-
  fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the
  send_message/send_message_to_phone MCP tools accept files as a list of http(s)
  URLs, which the server downloads and attaches to the outgoing Telegram
  message. Downloa…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-184
  - CWE-918
vendor: leshchenko1979
product: fast-mcp-telegram
affected:
  - fast-mcp-telegram < 30.1
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T17:17:50.007'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55096'
references:
  - url: >-
      https://github.com/leshchenko1979/fast-mcp-telegram/commit/e6b3032cfc906e14f5b84f2c2b8ec378eb457e57
    label: security-advisories@github.com
  - url: 'https://github.com/leshchenko1979/fast-mcp-telegram/releases/tag/0.30.1'
    label: security-advisories@github.com
  - url: >-
      https://github.com/leshchenko1979/fast-mcp-telegram/security/advisories/GHSA-xr72-j7vj-vp7g
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T17:16:27.812Z'
---

## Overview

fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's literal hostname string but never resolves DNS. The fetch (httpx.AsyncClient.get) does its own resolution at request time. Consequently a hostname that resolves to a loopback / private / link-local address passes the guard and is fetched — even with the secure defaults block_private_ips=True and allow_http_urls=False. Because the fetched body is returned to the attacker as a Telegram file attachment, this is a full-read, exfiltrating SSRF, not blind. This issue has been patched in version 30.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
