Edit history

Earlier versions of API allows sending messages in system DMs, newest first.

Current version | Edited by Rex
Changes
[image](https://feedback.fluxer.com/p/424#f-414)Removed: ### ChecksRemoved: Removed: - ☑ I searched for existing issues and didn't find a duplicate.Removed:
Show

API allows sending messages in system DMs

Summary

It is possible to send a message in a channel reserved for official system messages, the API doesn't prevent it. I'm not reporting this as a security vulnerability since this API behavior can't be used for anything harmful. Even though this is not a bug users will see, I think it's still worth fixing, as it is unintended behavior.

Steps to reproduce

  1. Send a message in any DM channel while having the network tab of the browser console opened.
  2. Copy the "fetch" of the network request related to the message.
  3. Change the URI to be https://web.fluxer.app/api/v1/channels/%3Csystem channel id>/messages. Replace the <system channel id> with the ID of the system DM channel (right click -> copy channel ID).
  4. Change the "referrer" to the same URI.
  5. (You can also modify the "body".)
  6. Send the request through the browser console. This will send a message in the system DM.

Environment (optional)

stable build 87 (28da28c), 2026-03-11 14:24:05 UTC, Chrome 144.0.0.0, Linux (x86)

Logs or screenshots (optional)

image
Original by Rex
Show

API allows sending messages in system DMs

Summary

It is possible to send a message in a channel reserved for official system messages, the API doesn't prevent it. I'm not reporting this as a security vulnerability since this API behavior can't be used for anything harmful. Even though this is not a bug users will see, I think it's still worth fixing, as it is unintended behavior.

Steps to reproduce

  1. Send a message in any DM channel while having the network tab of the browser console opened.
  2. Copy the "fetch" of the network request related to the message.
  3. Change the URI to be https://web.fluxer.app/api/v1/channels/%3Csystem channel id>/messages. Replace the <system channel id> with the ID of the system DM channel (right click -> copy channel ID).
  4. Change the "referrer" to the same URI.
  5. (You can also modify the "body".)
  6. Send the request through the browser console. This will send a message in the system DM.

Environment (optional)

stable build 87 (28da28c), 2026-03-11 14:24:05 UTC, Chrome 144.0.0.0, Linux (x86)

Logs or screenshots (optional)

image

Checks

  • ☑ I searched for existing issues and didn't find a duplicate.