Executive brief
Quest Bot is an open-source Discord bot used for server moderation and support. A vulnerability in the bot's automatic role assignment feature allows users with limited server management permissions to grant themselves or others full Administrator access. This could lead to a complete takeover of the Discord server, allowing an attacker to delete channels, ban members, or access private data.
Technical details
A privilege escalation vulnerability exists in Quest Bot's /autorole command due to improper authorization checks. While the command requires 'Manage Server' permissions, it fails to verify if the user has 'Manage Roles' or 'Administrator' permissions before allowing them to configure which roles are automatically assigned to new members. An attacker can configure the bot to assign a role with Administrator privileges to new accounts. When the attacker joins the server with a secondary account, the bot (if it has sufficient hierarchy) assigns the administrative role, resulting in a full server takeover. This has been patched in version 1.0.3.
Affected products
- duck-organization Quest Bot < 1.0.3
Timeline
- 2026-05-17: patched: Version 1.0.3 released
- 2026-06-11: disclosed: CVE-2026-47169 published