VYPR

Trinity

by Abilityai

CVEs (1)

  • CVE-2026-108756MedOct 11, 2026
    risk 0.35cvss 5.4epss —

    Abilityai Trinity through 0.9.5 contains a missing authorization vulnerability in the Telegram router that allows agent-scoped MCP API keys to perform human-only binding operations. Attackers controlling an agent, typically via prompt injection, can send messages through the…