PT-2026-48712 · Quest Bot · Quest-Bot
CVE-2026-47173
·
Published
2026-06-11
·
Updated
2026-06-11
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Quest Bot versions prior to 1.0.3
Description
A normal user can create a ticket with a reason containing @everyone, @here, user mentions, or role mentions. The bot posts this attacker-controlled reason into the new ticket channel without suppressing mentions. If the bot possesses the necessary permissions, this allows an attacker to trigger notifications for staff or all users with access to the ticket channel.
Recommendations
Update to version 1.0.3.
Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quest-Bot