PT-2026-48859 · Quest Bot · Quest-Bot

CVE-2026-47196

·

Published

2026-06-12

·

Updated

2026-06-12

CVSS v4.0

8.4

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Quest Bot versions prior to 1.1.6
Description The automod add command trims user input but fails to reject empty results. If a rule containing only whitespace is added, an empty word is stored. The message listener subsequently uses the content.includes("") check, which always evaluates to true, leading the bot to delete every message in the guild that is not sent by a bot.
Recommendations Update to version 1.1.6.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47196
GHSA-FGWG-6PX5-CXP5

Affected Products

Quest-Bot