[SECURITY] HIGH: HTML injection in Telegram messages #5
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Severity: HIGH
Event titles from Polymarket API are inserted directly into Telegram messages with
parse_mode=HTMLwithout escaping. Characters like<,>,&are not escaped.Location
scripts/browse.pylines 614-661 (send_to_telegram())Attack Scenario
<script>alert('XSS')</script>Recommended Fix
Reference
See
reviews/2026-03-25.mdSection 6.3