Vulnerability  ·  2026-10-12

Abilityai Trinity: agent-scoped MCP keys can perform human-only Telegram binding operations (prompt-injection reachable) (CVSS 5.4)

VulnerabilityMedium impactGlobalCVE-2026-108756
VulnCheck published CVE-2026-108756 (published 2026-10-11, CVSS 5.4, CWE-862) for Abilityai Trinity ≤ 0.9.5: the Telegram router lacks authorization separating agent-scoped keys from human binding actions, so compromised agents can rebind/delete the owner bot token. Verified against NVD REST API.
A narrow authorization-boundary flaw in an agent framework's Telegram channel: it converts prompt-injected agent control into persistent hijack of the human-facing bot channel. Low CVSS and narrow exposure keep it at precision-tier C, but it is a real agent-authz boundary break.
A prompt-injected or otherwise attacker-controlled agent uses agent-scoped MCP API keys against Telegram router routes intended for human-only binding operations (CWE-862), taking over the owner's bot binding.
Abilityai Trinity through 0.9.5
Upgrade past 0.9.5 and separate agent-scoped keys from human-bound operations. Advisory: https://www.vulncheck.com/advisories/abilityai-trinity-through-0.9.5-missing-authorization-in-telegram-binding-routes
NVD CVE-2026-108756VulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →