Executive brief
Quest Bot is an open-source Discord bot used for server moderation and support. A flaw in how the bot handles moderation commands allows low-level moderators to trick the bot into sending mass notifications (like @everyone) that they would otherwise not have permission to send. This can be used to disrupt large servers and cause unwanted notification spam that appears to come from a trusted source.
Technical details
Quest Bot prior to version 1.0.4 is vulnerable to improper output escaping (CWE-116) within its moderation commands, including /ban, /kick, and /mute. The bot echoes user-provided 'reason' text in public confirmation messages without suppressing Discord mentions. An attacker with basic moderation privileges but lacking 'Mention Everyone' permissions can include @everyone or @here in the reason field. Because the bot itself typically possesses high-level permissions, Discord parses these strings as valid mass-mentions, allowing the attacker to bypass intended permission restrictions. The issue is present even if the moderation action is canceled, as the confirmation message is sent immediately.
Affected products
- duck-organization Quest Bot < 1.0.4
Timeline
- 2026-05-17: patched: Version 1.0.4 released to fix mention parsing.
- 2026-06-11: disclosed: CVE-2026-47175 published.