CVE-2026-47189

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the AutoMod remove flow looks up and deletes rules by global database ID without verifying that the rule belongs to the guild where the command is executed. A user can learn a victim guild’s AutoMod rule ID through autocomplete, then remove that rule from another guild where they have Manage Server. This issue has been patched in version 1.0.5.
CVSS

No CVSS.

Configurations

No configuration.

History

11 Jun 2026, 20:16

Type Values Removed Values Added
References () https://github.com/duck-organization/questbot/security/advisories/GHSA-6rv9-6p24-w955 - () https://github.com/duck-organization/questbot/security/advisories/GHSA-6rv9-6p24-w955 -

11 Jun 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-11 19:16

Updated : 2026-06-17 10:54


NVD link : CVE-2026-47189

Mitre link : CVE-2026-47189

CVE.ORG link : CVE-2026-47189


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key