Herdr Telegram Remote can inject text and key events into coding-agent panes. Treat the Telegram bot token and every authorized Telegram account as having the same practical access as the local user running Codex or Claude Code.
Security fixes are provided for the latest tagged beta/release only.
Use GitHub's private vulnerability reporting for this repository. Do not open a public issue containing bot tokens, chat IDs, user IDs, pane transcripts, screenshots, filesystem paths, or agent session IDs.
Include the affected version, operating system, Herdr version, reproduction steps, and impact. Replace all credentials and personal identifiers with placeholders.
- Open @BotFather in Telegram.
- Revoke/regenerate the affected bot token immediately.
- Replace
TELEGRAM_BOT_TOKENin.envand keep the file mode at600. - Restart the launchd/systemd service.
- Review
ALLOWED_USER_IDS,TELEGRAM_CHAT_ID, local logs, and recent agent activity before resuming remote control.
TELEGRAM_CHAT_IDandALLOWED_USER_IDSare both enforced.- The bot does not create an authentication boundary inside Codex or Claude Code. The selected agent still has whatever local permissions it was started with.
- Natural-language prompts can request destructive work even when a slash command is not in the explicit dangerous-command list.
/restart xstarts Claude Code with permission bypass and therefore requires a separate confirmation token.- Screenshots and uploaded images may contain secrets. Keep the Telegram group private and review PRIVACY.md.
This is an independent community project and is not affiliated with Herdr, OpenAI, Anthropic, or Telegram.