Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, several moderation commands echo user-controlled reason text in public bot replies without disabling mention parsing. A moderator who does not have permission to mention everyone can still make the bot send @everyone or @here if the bot has that permission. This issue has been patched in version 1.0.4.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, several moderation commands echo user-controlled reason text in public bot replies without disabling mention parsing. A moderator who does not have permission to mention everyone can still make the bot send @everyone or @here if the bot has that permission. This issue has been patched in version 1.0.4. | |
| Title | Quest Bot: Moderation reason fields allow bot-powered `@everyone` / `@here` pings | |
| Weaknesses | CWE-116 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-11T18:29:43.264Z
Reserved: 2026-05-18T21:25:34.497Z
Link: CVE-2026-47175
No data.
Status : Received
Published: 2026-06-11T19:16:45.730
Modified: 2026-06-11T19:16:45.730
Link: CVE-2026-47175
No data.
OpenCVE Enrichment
No data.