Description
VoidBot Open-Source is a customizable Discord bot. VoidBot Open-Source versions 0.0.1 through 0.8.1 contain a vulnerability in the command handler where permission checks are not properly enforced for certain administrative commands. This allows users without the required roles or privileges to execute sensitive commands such as `ban`, `kick`, or `shutdown`, potentially disrupting server operations. Version 1.0.0 fixes the issue.
Problem types
CWE-863: Incorrect Authorization
Product status
References
github.com/...source/security/advisories/GHSA-6rr8-9c8q-m5rv
discordjs.guide/popular-topics/permissions.html