Junglewise Threat Intelligence

CVE-2026-47171: duck-organization Quest Bot improper output escaping in reminders

CVE-2026-47171 · Severity: info · CVSS 5.3 · Published 2026-06-11

Technologies: Duck-Organization Quest Bot. Vendors: Duck-Organization.

Executive brief

Quest Bot is an open-source Discord bot used for server moderation and utility tasks. A vulnerability in the reminder feature allows any user to schedule messages that trigger mass notifications (like @everyone) if the bot has the necessary permissions. This can be used to bypass typical user restrictions, causing widespread disruption and unwanted notifications across a Discord server.

Technical details

Quest Bot prior to version 1.0.3 is vulnerable to improper output escaping (CWE-116) within its reminder functionality. The bot fails to sanitize user-provided strings or suppress mass mentions when replaying stored reminder messages. An attacker with basic user privileges can create a reminder containing '@everyone' or '@here' tags; when the scheduled task executes, the bot sends the message to the channel. If the bot has the 'Mention @everyone, @here, and All Roles' permission, Discord will process these as valid mass notifications. This issue is patched in version 1.0.3.

Affected products

  • duck-organization Quest Bot < 1.0.3

Timeline

  • 2026-05-17: patched: Version 1.0.3 released
  • 2026-05-17: advisory: GitHub Security Advisory published
  • 2026-06-11: disclosed: CVE published to NVD

References

Related threats