MEDIUM
Abilityai
CVE published 2026-10-11
CVE-2026-108756
CVE-2026-108756 Abilityai Trinity through 0.9.5 Missing Authorization in Telegram Binding Routes. The vulnerability allows agent-scoped MCP API keys to perform human-only binding operations, potentially leading to unauthorized access or manipulation of bindings. Defenders should assess exposure and prioritize remediation, focusing on restricting access to Telegram binding routes and ensuring proper author [truncated]