kedi ElectronCord is a bot management tool for Discord. Commit aaaeaf4e6c99893827b2eea4dd02f755e1e24041 exposes an account access token in the `config.json` file. Malicious actors could potentially exploit this vulnerability to gain unauthorized access to sensitive information or perform malicious actions on behalf of the repository owner. As of time of publication, it is unknown whether the owner of the repository has rotated the token or taken other mitigation steps aside from informing users of the situation.
History

Wed, 05 Feb 2025 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Openjsf
Openjsf electroncord
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:openjsf:electroncord:*:*:*:*:*:discord:*:*
Vendors & Products Openjsf
Openjsf electroncord

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-28T16:52:25.209Z

Reserved: 2024-02-14T17:40:03.688Z

Link: CVE-2024-26136

cve-icon Vulnrichment

Updated: 2024-08-01T23:59:32.535Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-20T22:15:08.767

Modified: 2025-02-05T22:35:04.903

Link: CVE-2024-26136

cve-icon Redhat

No data.