Skip to content

The Telegram bot is unverified and accessible to anyone. #42

@kinogram

Description

@kinogram

The Telegram bot is unverified and accessible to anyone.

How could no one have noticed this huge security vulnerability? After binding the Telegram bot and running the backend program, whenever the bot receives a prompt, regardless of who sent it, it will forward it to Codex. This is essentially opening your computer to the entire world! You can refer to OpenClaw's Telegram bot mechanism.

Solution: Add Telegram accounts to a whitelist. Only allow whitelisted IDs to access the bot.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions