PT-2026-3920 · Discord · Discord

Xmrcat

·

Publicado

2026-01-22

·

Atualizado

2026-01-22

·

CVE-2026-24332

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discord versions through 2026-01-16
Description The software allows gathering information about whether a user’s client state is Invisible (and not actually offline). The response to a WebSocket API request includes the user in the presences array with a status of "offline," while truly offline users are omitted from this array. This behavior is inconsistent with the user interface description of Invisible, which states that users will appear offline. The issue involves the handling of user presence information via the WebSocket API. Specifically, the /presences API endpoint reveals the status of users who have set their status to Invisible. The status variable within the API response indicates whether a user is online, offline, idle, or do not disturb.
Recommendations Versions through 2026-01-16 should be updated when a fix becomes available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24332

Produtos afetados

Discord