Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a normal user can create a reminder whose message contains @everyone or @here. When the reminder triggers, the bot sends the stored message back into the channel without suppressing mass mentions. If the bot has permission to mention everyone, the reminder can ping the entire server or channel later. This issue has been patched in version 1.0.3.
Metrics
Affected Vendors & Products
References
History
Fri, 12 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Duck-organization
Duck-organization quest-bot |
|
| Vendors & Products |
Duck-organization
Duck-organization quest-bot |
Thu, 11 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a normal user can create a reminder whose message contains @everyone or @here. When the reminder triggers, the bot sends the stored message back into the channel without suppressing mass mentions. If the bot has permission to mention everyone, the reminder can ping the entire server or channel later. This issue has been patched in version 1.0.3. | |
| Title | Quest Bot: Reminder messages allow stored mass mentions through `@everyone` and `@here` | |
| Weaknesses | CWE-116 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-06-11T18:28:07.651Z
Updated: 2026-06-11T18:59:23.300Z
Reserved: 2026-05-18T21:25:34.497Z
Link: CVE-2026-47171
Updated: 2026-06-11T18:59:05.539Z
Status : Deferred
Published: 2026-06-11T19:16:45.080
Modified: 2026-06-11T20:58:18.123
Link: CVE-2026-47171
No data.
ReportizFlow