← back
CVE-2026-47163

Quest Bot: Unprivileged users can create and remove AutoMod rules.

CVSS 7.2 HIGHEPSS 0.2%CWE-862
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.2EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
11 Jun 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.1, any guild member who can invoke slash commands can use /automod add, /automod remove, and /automod list because the command has no Discord default permission requirement and no runtime moderator permission check. An attacker can add a rule matching common text and make the bot delete other users’ messages. This issue has been patched in version 1.0.1.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →