Telnyx MCP 服务器将其 HTTP 传输暴露在所有网络接口上,且未要求调用方提供身份凭证。 在根路径上以绑定到所有接口的监听器提供 MCP 服务,并在未提供认证头时不会报错的解析模式下解析调用方的认证头,因此任何未携带任何凭证的请求都能完成初始化并触发工具执行。调度逻辑会将服务器自身存储的凭证(包括 Telnyx API 密钥、客户端密钥以及代码执行密钥)转发至上游端点,导致任何能够访问该端口的未认证调用方都能以这些凭证的身份行事。当前代码已将默认绑定改为回环地址,要求提供服务器 API 密钥,并在中间件中
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| team-telnyx | telnyx-mcp | 0 ~ 6.83.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet