CVE-2026-49347

Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly create new ticket channels. The latest release still creates a new database ticket and Discord channel for every completed ticket modal submission, without checking whether the same user already has an open ticket and without applying a cooldown. This issue has been patched in version 1.1.8.
CVSS

No CVSS.

Configurations

No configuration.

History

12 Jun 2026, 15:16

Type Values Removed Values Added
References () https://github.com/duck-organization/questbot/security/advisories/GHSA-r56q-v363-367q - () https://github.com/duck-organization/questbot/security/advisories/GHSA-r56q-v363-367q -

12 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 13:16

Updated : 2026-06-12 15:56


NVD link : CVE-2026-49347

Mitre link : CVE-2026-49347

CVE.ORG link : CVE-2026-49347


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling