Note that the command they use, poll, requires to login first, which means they also had some valid credentials somehow.
In addition, they seemed to have access to the source code, whereas the opensource version hasn't been updated in more than 8 years.
Maybe this is the result of a whitebox security audit?