Junglewise Threat Intelligence

CVE-2026-47175: Quest Bot unauthorized mass mentions in moderation commands

CVE-2026-47175 · Severity: info · CVSS 2.3 · Published 2026-06-11

Technologies: Duck-Organization Quest Bot. Vendors: Duck-Organization.

Executive brief

Quest Bot is an open-source Discord bot used for server moderation and support. A flaw in how the bot handles moderation commands allows low-level moderators to trick the bot into sending mass notifications (like @everyone) that they would otherwise not have permission to send. This can be used to disrupt large servers and cause unwanted notification spam that appears to come from a trusted source.

Technical details

Quest Bot prior to version 1.0.4 is vulnerable to improper output escaping (CWE-116) within its moderation commands, including /ban, /kick, and /mute. The bot echoes user-provided 'reason' text in public confirmation messages without suppressing Discord mentions. An attacker with basic moderation privileges but lacking 'Mention Everyone' permissions can include @everyone or @here in the reason field. Because the bot itself typically possesses high-level permissions, Discord parses these strings as valid mass-mentions, allowing the attacker to bypass intended permission restrictions. The issue is present even if the moderation action is canceled, as the confirmation message is sent immediately.

Affected products

  • duck-organization Quest Bot < 1.0.4

Timeline

  • 2026-05-17: patched: Version 1.0.4 released to fix mention parsing.
  • 2026-06-11: disclosed: CVE-2026-47175 published.

References

Related threats