CVE-2026-47195
Quest Bot: Per-channel permission overwrite bypass in purge and slowmode commands.
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level permissions on the invoking member. They do not check the memberβs effective permissions in the channel where the command is run. A user denied channel-level moderation permissions can still delete messages or change slowmode through the bot. This issue has been patched in version 1.1.6.
| CWE | CWE-863 |
| Vendor | duck-organization |
| Product | questbot |
| Published | Jun 12, 2026 |
| Last Updated | Jun 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for duck-organization questbot
Be the first to know when new unknown vulnerabilities affecting duck-organization questbot are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
duck-organization / questbot
< 1.1.6