This repository has been archived by the owner on Aug 19, 2023. It is now read-only.
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Prevent edge-case exploitation that allows execution of arbitrary fan…
…tasy commands. This commit replaces \r\n with '. ' in tweets. An edge-case issue where you may be able to exploit the bot having op. Should you be the one being tracked, you could insert a newline in your tweet, and follow it up for "!ban <someone>" to execute a fantasy command. This exploit requires a lot of requirements to be met. Mainly the fact that the bot has permissions in the channel, and that the followed person is associated and aware of the possibility.
- Loading branch information