Duck Organization Quest Bot是Duck Organization组织的一款云计算虚拟化软件。 Quest Bot 1.1.6之前版本存在安全漏洞,该漏洞源于绕过Discord正常角色层级保护,可能导致低级别管理员越权管理高级别用户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| duck-organization | questbot | < 1.1.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| duck-organization | questbot | < 1.1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47195 | Quest Bot: Per-channel permission overwrite bypass in purge and slowmode commands. | |
| CVE-2026-47196 | Quest Bot: Empty automod rule causes every guild message to be deleted | |
| CVE-2026-48485 | Quest Bot: Stored warn reasons can still trigger bot-powered mass mentions through `/warns | |
| CVE-2026-49347 | Quest Bot: Ticket creation has no per-user open-ticket limit or cooldown |
No comments yet