CVE-2026-47175
Quest Bot: Moderation reason fields allow bot-powered `@everyone` / `@here` pings
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, several moderation commands echo user-controlled reason text in public bot replies without disabling mention parsing. A moderator who does not have permission to mention everyone can still make the bot send @everyone or @here if the bot has that permission. This issue has been patched in version 1.0.4.
| CWE | CWE-116 |
| Vendor | duck-organization |
| Product | quest-bot |
| Published | Jun 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for duck-organization quest-bot
Be the first to know when new unknown vulnerabilities affecting duck-organization quest-bot are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
duck-organization / quest-bot
< 1.0.4