Abilityai Trinity through 0.9.5 contains a missing authorization vulnerability in the Telegram router that allows agent-scoped MCP API keys to perform human-only binding operations. Attackers controlling an agent, typically via prompt injection, can send messages through the owner's bot token, replace the binding with their own token, or delete it.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Abilityai Trinity through 0.9.5 contains a missing authorization vulnerability in the Telegram router that allows agent-scoped MCP API keys to perform human-only binding operations. Attackers controlling an agent, typically via prompt injection, can send messages through the owner's bot token, replace the binding with their own token, or delete it. | |
| Title | Abilityai Trinity through 0.9.5 Missing Authorization in Telegram Binding Routes | |
| First Time appeared |
Trinity Project
Trinity Project trinity |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:trinity_project:trinity:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Trinity Project
Trinity Project trinity |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T12:19:54.615Z
Reserved: 2026-10-11T01:57:24.159Z
Link: CVE-2026-108756
No data.
Status : Received
Published: 2026-10-11T13:17:20.680
Modified: 2026-10-11T13:17:20.680
Link: CVE-2026-108756
No data.
OpenCVE Enrichment
Updated: 2026-10-11T14:00:18Z
Weaknesses