Skip to content

Telegram bot token exposure

High
soruly published GHSA-8rg8-9337-9v8f Sep 28, 2020

Package

npm trace.moe-telegram-bot (npm)

Affected versions

2.1.1

Patched versions

2.1.2

Description

Impact

trace.moe-telegram-bot may expose Telegram Bot's API token for any user hosting their own Telegram bot. When image URL failed to fetch by trace.moe API, the error message may contain telegram bot's API token.

Patches

Issue was patched in commit 65a0b74
Recommend update to version 2.1.2 and then reset your Telegram Bot API token immediately.

Workarounds

Downgrade to version before commit cf5779f , which doesn't support URL search and then reset your Telegram Bot API token.

References

image

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs