Sceawere
Vulnerability Detail
CVE-2026-108756UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Abilityai Trinity Unauthorized MCP Binding
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 4h ago
- Vendor
- Abilityai
- Product
- trinity
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Abilityai Trinity through 0.9.5 contains a missing authorization vulnerability in the Telegram router that allows agent-scoped MCP API keys to perform human-only binding operations. Attackers controlling an agent, typically via prompt injection, can send messages through the owner's bot token, replace the binding with their own token, or delete it.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-11T13:17:20.680Z",
"pubdate": "2026-10-11T13:17:20.680Z",
"executiveSummary": "Abilityai Trinity versions up to and including 0.9.5 are susceptible to a missing authorization vulnerability within the Telegram router component.\nThis flaw permits entities possessing agent-scoped Model Context Protocol (MCP) API keys to perform administrative binding operations strictly reserved for human users.\nThe vulnerability allows an attacker who has compromised an agent—most effectively via prompt injection techniques—to execute unauthorized actions using the victim's Telegram bot token.\nImpact includes the ability for an attacker to hijack the bot's communication channel, substitute the legitimate owner's binding with an attacker-controlled token, or unilaterally delete existing bindings.\nThe risk is severe as it effectively grants an external attacker the identity and control capabilities of the compromised bot, circumventing the intended security model where only the authenticated owner should manage administrative configurations.\nSuccessful exploitation requires the attacker to first establish control over an agent, which can then be leveraged to interact with the vulnerable Telegram router API without proper authorization checks.",
"technicalDetails": "The vulnerability resides in the Telegram router module of the Abilityai Trinity framework, specifically within the authorization logic governing MCP API keys. The root cause is an improper access control implementation where the system fails to verify the privilege level of the API key before executing sensitive administrative functions.\nIn the affected versions (0.9.5 and below), the Telegram router does not distinguish between user-level and agent-level permissions during the processing of binding-related requests. Consequently, an agent-scoped MCP API key, which should be restricted to limited agent-specific tasks, is erroneously permitted to invoke functions intended solely for administrative user management.\nThe attack flow typically initiates through a prompt injection vector. An attacker sends a malicious prompt to the target agent, effectively 'jailbreaking' the agent's expected behavior. Once the attacker gains control of the agent's logic flow, they can transmit crafted requests to the Telegram router's internal API endpoints. Because the router performs a deficient validation of the provided MCP API key, it interprets the agent's request as legitimate commands from the owner.\nSpecifically, the attacker can leverage this unauthorized access to manipulate the bot's state. By invoking the update or delete functions within the binding service, the attacker can swap the original Telegram bot token linked to the instance for an attacker-controlled token. This results in the redirection of all subsequent bot traffic to an external listener, effectively performing a man-in-the-middle attack or full service hijacking. Furthermore, the attacker can delete the legitimate owner's binding, resulting in a denial-of-service condition for the authorized user and potential complete loss of account control.\nThis vulnerability highlights a critical failure in the Principle of Least Privilege (PoLP) and the lack of robust request validation in the framework's internal API communications. By allowing low-privileged agent keys to interface with high-privileged management functions, the system exposes a significant attack surface that transforms an agent-level compromise into an administrative-level breach."
}