CVE-2026-47195

Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level permissions on the invoking member. They do not check the member’s effective permissions in the channel where the command is run. A user denied channel-level moderation permissions can still delete messages or change slowmode through the bot. This issue has been patched in version 1.1.6.
CVSS

No CVSS.

Configurations

No configuration.

History

12 Jun 2026, 14:16

Type Values Removed Values Added
References () https://github.com/duck-organization/questbot/security/advisories/GHSA-2wf8-554w-hrj9 - () https://github.com/duck-organization/questbot/security/advisories/GHSA-2wf8-554w-hrj9 -

12 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 13:16

Updated : 2026-06-12 15:56


NVD link : CVE-2026-47195

Mitre link : CVE-2026-47195

CVE.ORG link : CVE-2026-47195


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization