Vulnerability Description
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, several moderation commands echo user-controlled reason text in public bot replies without disabling mention parsing. A moderator who does not have permission to mention everyone can still make the bot send @everyone or @here if the bot has that permission. This issue has been patched in version 1.0.4.
Related Weaknesses (CWE)
References
- https://github.com/duck-organization/questbot/releases/tag/questbot-v1.0.4
- https://github.com/duck-organization/questbot/security/advisories/GHSA-556x-7wgq
- https://github.com/duck-organization/questbot/security/advisories/GHSA-556x-7wgq
FAQ
What is CVE-2026-47175?
CVE-2026-47175 is a documented vulnerability. Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, several moderation commands echo user-controlled reason text in public bot replies wi...
How severe is CVE-2026-47175?
CVSS scoring is not yet available for CVE-2026-47175. Check NVD for updates.
Is there a patch for CVE-2026-47175?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.