PT-2026-48710 · Quest Bot · Quest-Bot

CVE-2026-47171

·

Published

2026-06-11

·

Updated

2026-06-11

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Quest Bot versions prior to 1.0.3
Description A flaw allows a standard user to create a reminder containing @everyone or @here. When the reminder triggers, the bot sends the message without suppressing mass mentions. If the bot possesses the necessary permissions, this results in an unauthorized ping of the entire server or channel.
Recommendations Update to version 1.0.3.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47171
GHSA-VMGG-F3M4-6FCV

Affected Products

Quest-Bot