Vulnerability Description
kedi ElectronCord is a bot management tool for Discord. Commit aaaeaf4e6c99893827b2eea4dd02f755e1e24041 exposes an account access token in the `config.json` file. Malicious actors could potentially exploit this vulnerability to gain unauthorized access to sensitive information or perform malicious actions on behalf of the repository owner. As of time of publication, it is unknown whether the owner of the repository has rotated the token or taken other mitigation steps aside from informing users of the situation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openjsf | Electroncord | < 2024-02-19 |
Related Weaknesses (CWE)
References
- https://github.com/kedi/ElectronCord/commit/aaaeaf4e6c99893827b2eea4dd02f755e1e2Patch
- https://github.com/kedi/ElectronCord/security/advisories/GHSA-ppwc-5vwp-mhw8Vendor Advisory
- https://github.com/kedi/ElectronCord/commit/aaaeaf4e6c99893827b2eea4dd02f755e1e2Patch
- https://github.com/kedi/ElectronCord/security/advisories/GHSA-ppwc-5vwp-mhw8Vendor Advisory
FAQ
What is CVE-2024-26136?
CVE-2024-26136 is a vulnerability with a CVSS score of 7.5 (HIGH). kedi ElectronCord is a bot management tool for Discord. Commit aaaeaf4e6c99893827b2eea4dd02f755e1e24041 exposes an account access token in the `config.json` file. Malicious actors could potentially ex...
How severe is CVE-2024-26136?
CVE-2024-26136 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-26136?
Check the references section above for vendor advisories and patch information. Affected products include: Openjsf Electroncord.