Junglewise Threat Intelligence

CVE-2026-47189: Quest Bot authorization bypass in AutoMod rule removal

CVE-2026-47189 · Severity: info · CVSS 8.3 · Published 2026-06-11

Technologies: Duck-Organization Quest Bot. Vendors: Duck-Organization.

Executive brief

Quest Bot is an open-source Discord bot used for server moderation and utility tasks. A security flaw allows users to delete moderation rules (such as blocked words) from servers they do not manage. By exploiting this, an attacker can disable a community's automated defenses, potentially leading to unmoderated content or harassment.

Technical details

An authorization bypass exists in the AutoMod removal flow of Quest Bot due to insecure direct object references (IDOR). The bot's autocomplete handler for the '/automod remove' command leaks global database IDs for moderation rules to any user, regardless of their permissions in the victim guild. The removal handler then deletes rules based on these global IDs without verifying that the rule belongs to the guild where the command is being executed. An attacker with 'Manage Server' permissions in any guild can use a leaked ID to delete rules from a different victim guild. This issue is fixed in version 1.0.5 by implementing guild-ownership checks during the deletion process.

Affected products

  • duck-organization Quest Bot <= 1.0.4

Timeline

  • 2026-05-18: patched: Version 1.0.5 released with fix.
  • 2026-06-11: disclosed: CVE-2026-47189 published.

References

Related threats