CVE-2026-108756
Received Received - Intake

Abilityai Trinity Agent Authorization Bypass via Telegram Router

Vulnerability report for CVE-2026-108756, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Abilityai Trinity through 0.9.5 contains a missing authorization vulnerability in the Telegram router that allows agent-scoped MCP API keys to perform human-only binding operations. Attackers controlling an agent, typically via prompt injection, can send messages through the owner's bot token, replace the binding with their own token, or delete it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Abilityai trinity 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Abilityai Trinity through 0.9.5 has a missing authorization flaw in its Telegram router. Agent-scoped MCP API keys can perform human-only binding operations without proper checks. Attackers exploiting this can send messages via the owner's bot token, replace the binding with their own token, or delete it entirely.

Detection Guidance

Check for unauthorized Telegram bot token changes or deletions in Trinity's logs. Inspect network traffic for unexpected POST requests to /api/agents/{name}/telegram endpoints. Verify if agent-scoped API keys are performing human-only operations like binding configuration or message sending.

Impact Analysis

If you use Abilityai Trinity, an attacker could hijack your bot token, impersonate your agent, or disrupt its operations. This could lead to unauthorized actions performed under your identity, potential data leaks, or service disruption.

Compliance Impact

This vulnerability could lead to unauthorized access or data exposure, violating GDPR's data protection principles or HIPAA's integrity and confidentiality requirements. Organizations may face compliance penalties if such breaches occur due to insufficient authorization controls.

Mitigation Strategies

Immediately revoke any agent-scoped MCP API keys and review all active bindings in the Telegram router. Monitor for unauthorized token replacements or deletions. Ensure prompt injection protections are in place to prevent agent compromise.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108756. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart