MediumVulnerabilityLLM-specific
CVE-2026-108756: Abilityai Trinity missing authorization in Telegram router binding operations
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-108756
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
Summary
Abilityai Trinity through 0.9.5 has a missing authorization flaw in its Telegram router. Agent-scoped MCP API keys can perform binding operations that are meant only for humans. An attacker who controls an agent, typically through prompt injection, can send messages through the owner's bot token, replace the binding with their own token, or delete the binding.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- MediumCVE-2026-108759: mistral.rs sandbox escape via symlinks in mistralrs-code-execSimilar attack · NVD/CVE Database
- MediumCVE-2026-108600: open-multi-agent link following flaw in file_write tool sandboxSimilar attack · NVD/CVE Database
- MediumCVE-2026-108599: phi symlink escape in permission gate allows writes outside workspaceSimilar attack · NVD/CVE Database
- MediumCVE-2026-108592: mini-swe-agent information exposure in BubblewrapEnvironment sandboxSimilar attack · NVD/CVE Database
- MediumCVE-2026-108583: zotero-mcp server-side request forgery via zotero_add_by_urlSimilar attack · NVD/CVE Database