CVE-2026-108756 PUBLISHED

Abilityai Trinity through 0.9.5 Missing Authorization in Telegram Binding Routes

Assigner: VulnCheck
Reserved: 11.10.2026 Published: 11.10.2026 Updated: 11.10.2026

Abilityai Trinity through 0.9.5 contains a missing authorization vulnerability in the Telegram router that allows agent-scoped MCP API keys to perform human-only binding operations. Attackers controlling an agent, typically via prompt injection, can send messages through the owner's bot token, replace the binding with their own token, or delete it.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor Abilityai
Product trinity
Versions Default: unaffected
  • affected from 0 to 0.9.5 (incl.)

Credits

  • HaiND from the Post and Telecommunication Institute of Technology finder

References

Problem Types

  • Missing Authorization CWE