CVE-2026-108756
Abilityai Trinity through 0.9.5 Missing Authorization in Telegram Binding Routes
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
Abilityai Trinity through 0.9.5 contains a missing authorization vulnerability in the Telegram router that allows agent-scoped MCP API keys to perform human-only binding operations. Attackers controlling an agent, typically via prompt injection, can send messages through the owner's bot token, replace the binding with their own token, or delete it.
| CWE | CWE-862 |
| Vendor | abilityai |
| Product | trinity |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for abilityai trinity
Be the first to know when new medium vulnerabilities affecting abilityai trinity are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
Affected Versions
Abilityai / trinity
0 โค 0.9.5
References
hackmd.io: https://hackmd.io/@haind/rJ2OBa8sfl github.com: https://github.com/Abilityai/trinity/blob/e38c1c0f2567c602541c90c4c92152e99e6ead11/src/backend/routers/telegram.py#L168-L219 github.com: https://github.com/Abilityai/trinity/blob/e38c1c0f2567c602541c90c4c92152e99e6ead11/src/backend/routers/telegram.py#L258-L323 github.com: https://github.com/Abilityai/trinity vulncheck.com: https://www.vulncheck.com/advisories/abilityai-trinity-through-0.9.5-missing-authorization-in-telegram-binding-routes
Credits
HaiND from the Post and Telecommunication Institute of Technology