PT-2026-48861 · Quest Bot · Quest-Bot

CVE-2026-48485

·

Published

2026-06-12

·

Updated

2026-06-12

CVSS v4.0

2.1

Low

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Quest Bot versions prior to 1.1.6
Description Quest Bot suppresses mentions during several administrative actions, such as creating, unbanning, unwarning, kicking, muting, and unmuting. However, warning reasons stored in the system are printed by the /warns endpoint without mention suppression. This allows a moderator to include @everyone or @here in a warning reason, which can subsequently trigger a mass ping when the bot outputs that reason, provided the bot has the necessary permissions.
Recommendations Update to version 1.1.6.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48485
GHSA-XJM4-8GGW-8JWF

Affected Products

Quest-Bot