Executive brief
Quest Bot is an open-source Discord bot used for server moderation and utility tasks. A vulnerability in the reminder feature allows any user to schedule messages that trigger mass notifications (like @everyone) if the bot has the necessary permissions. This can be used to bypass typical user restrictions, causing widespread disruption and unwanted notifications across a Discord server.
Technical details
Quest Bot prior to version 1.0.3 is vulnerable to improper output escaping (CWE-116) within its reminder functionality. The bot fails to sanitize user-provided strings or suppress mass mentions when replaying stored reminder messages. An attacker with basic user privileges can create a reminder containing '@everyone' or '@here' tags; when the scheduled task executes, the bot sends the message to the channel. If the bot has the 'Mention @everyone, @here, and All Roles' permission, Discord will process these as valid mass notifications. This issue is patched in version 1.0.3.
Affected products
- duck-organization Quest Bot < 1.0.3
Timeline
- 2026-05-17: patched: Version 1.0.3 released
- 2026-05-17: advisory: GitHub Security Advisory published
- 2026-06-11: disclosed: CVE published to NVD