Skip to content
MediumVulnerabilityLLM-specific

CVE-2026-108756: Abilityai Trinity missing authorization in Telegram router binding operations

Identifier
CVE-2026-108756
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.

Summary

Abilityai Trinity through 0.9.5 has a missing authorization flaw in its Telegram router. Agent-scoped MCP API keys can perform binding operations that are meant only for humans. An attacker who controls an agent, typically through prompt injection, can send messages through the owner's bot token, replace the binding with their own token, or delete the binding.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.