Home

Description

Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly create new ticket channels. The latest release still creates a new database ticket and Discord channel for every completed ticket modal submission, without checking whether the same user already has an open ticket and without applying a cooldown. This issue has been patched in version 1.1.8.

PUBLISHED Reserved 2026-05-29 | Published 2026-06-12 | Updated 2026-06-12 | Assigner GitHub_M




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Problem types

CWE-770: Allocation of Resources Without Limits or Throttling

Product status

< 1.1.8
affected

References

github.com/...estbot/security/advisories/GHSA-r56q-v363-367q exploit

github.com/...estbot/security/advisories/GHSA-r56q-v363-367q

github.com/...nization/questbot/releases/tag/questbot-v1.1.8

cve.org (CVE-2026-49347)

nvd.nist.gov (CVE-2026-49347)

Download JSON