Only the latest published version of APTGRAM receives security fixes.
Users should update to the latest available release before reporting a security issue.
Please do not report security vulnerabilities through public GitHub issues or discussions.
When private vulnerability reporting is available for this repository, use the Report a vulnerability function in GitHub.
Include the following information where possible:
- the affected APTGRAM version
- the affected Linux distribution and version
- a clear description of the vulnerability
- steps required to reproduce the issue
- the potential security impact
- any suggested mitigation or fix
Do not include active Telegram Bot Tokens, credentials, passwords, private Chat IDs or other secrets in reports, screenshots or log files.
A Telegram Bot Token that has been exposed must be revoked immediately through @BotFather and replaced with a new token.
A leaked or publicly shared personal Bot Token is not, by itself, a vulnerability in APTGRAM.
Please allow reasonable time to investigate and fix a reported vulnerability before publishing details publicly.