Executive brief
Quest Bot is an open-source Discord bot used for server moderation and support tickets. A vulnerability allows any user to include special notification tags (like @everyone or specific role pings) within a ticket's 'reason' field. When the bot creates the ticket, it inadvertently triggers these notifications, allowing unauthorized users to spam staff or the entire server, potentially disrupting operations and abusing the bot's trusted status.
Technical details
Quest Bot prior to version 1.0.3 is vulnerable to a mention injection flaw due to improper encoding or escaping of user-provided output (CWE-116). When a user creates a ticket, the 'reason' provided in the Discord modal is posted by the bot into a new channel without suppressing mentions. An attacker can include payloads such as @everyone, @here, or role IDs (<@&ID>) to force the bot to ping users it has permission to mention. This allows for unauthorized mass notifications and staff harassment. The issue is fixed in version 1.0.3 by ensuring the bot suppresses or escapes mentions in the ticket-opening message.
Affected products
- duck-organization Quest Bot < 1.0.3
Timeline
- 2026-05-17: patched: Version 1.0.3 released and security advisory published on GitHub.
- 2026-06-11: disclosed: CVE-2026-47173 published to the NVD.