Telnyx MCP Server through 6.83.0 Missing Authentication on Streamable HTTP Transport
Published Aug 27, 2026
9.3
CRITICALCVSS 4.0
EPSS 0.73%
Description
The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path with a listener bound to all interfaces and parsed the caller's authentication headers in a mode that did not fail when they were absent, so a request without any credential completed initialisation and dispatched tools. Dispatch forwarded the server's own stored credentials, the Telnyx API key and client secret together with the code-execution key, to the upstream endpoint, so an unauthenticated caller able to reach the port acted with them. The current code defaults the host to loopback, requires a server API key, and enforces it in middleware.
Affected products
-
- Version 0StatusaffectedConstraints<=6.83.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Team-Telnyx | Telnyx-Mcp | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-67026 Advisory
- https://github.com/team-telnyx/telnyx-node product
- https://github.com/team-telnyx/telnyx-node/pull/450 issue-trackingpatch
- https://github.com/team-telnyx/telnyx-node/security/advisories/GHSA-46jp-xr2h-fw7h vendor-advisory
- https://www.vulncheck.com/advisories/telnyx-mcp-server-through-6.83.0-missing-authentication-on-streamable-http-transport third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-67026 | Advisory | |
| https://github.com/team-telnyx/telnyx-node | product | |
| https://github.com/team-telnyx/telnyx-node/pull/450 | issue-trackingpatch | |
| https://github.com/team-telnyx/telnyx-node/security/advisories/GHSA-46jp-xr2h-fw7h | vendor-advisory | |
| https://www.vulncheck.com/advisories/telnyx-mcp-server-through-6.83.0-missing-authentication-on-streamable-http-transport | third-party-advisory |
Change history (0)
No recorded changes yet.