Impact
The vulnerability resides in the Telegram router of Abilityai Trinity versions up to 0.9.5, where missing authorization checks allow an attacker possessing an agent‑scoped MCP API key to execute operations that are normally reserved for human users. These operations include creating, replacing, or deleting a binding that associates a bot token with the system. The outcome is that an attacker can compel the bot to send messages using a token they control, effectively hijacking the bot's communication capability and potentially leading to phishing, spam, or data exfiltration. The flaw is a classic missing privileges vulnerability (CWE‑862) that can be abused once the attacker gains any agent‑level access, commonly through prompt injection scenarios.
Affected Systems
The affected product is Abilityai Trinity up to and including version 0.9.5. No other versions or variants are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score is not available, preventing a precise estimate of exploitation probability. The lack of a KEV listing suggests no confirmed widespread exploitation yet, but the nature of the flaw means that any attacker who can compromise an agent can misuse the Telegram binding endpoints. The risk remains moderate to high for deployments where agent‑scoped keys could be leveraged by unauthenticated or partially authenticated actors, especially in environments that rely on the bot for critical communications.
OpenCVE Enrichment