Home

Description

Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the latest release suppresses mentions when creating, unbanning, unwarning, kicking, muting, and unmuting, but stored warning reasons are still printed by /warns without mention suppression. A moderator can create a warning with @everyone or @here in the reason, then make the bot later output that reason through /warns, causing a mass ping if the bot has permission. This issue has been patched in version 1.1.6.

PUBLISHED Reserved 2026-05-21 | Published 2026-06-12 | Updated 2026-06-12 | Assigner GitHub_M




LOW: 2.1CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Problem types

CWE-116: Improper Encoding or Escaping of Output

Product status

< 1.1.6
affected

References

github.com/...estbot/security/advisories/GHSA-xjm4-8ggw-8jwf exploit

github.com/...estbot/security/advisories/GHSA-xjm4-8ggw-8jwf

github.com/...nization/questbot/releases/tag/questbot-v1.1.6

cve.org (CVE-2026-48485)

nvd.nist.gov (CVE-2026-48485)

Download JSON