Discord · Red Discord Bot · CVE-2020-15140
**Name of the Vulnerable Software and Affected Versions**
Red Discord Bot versions prior to 3.3.11
**Description**
A remote code execution exploit has been discovered in the Trivia module, allowing Discord users with specifically crafted usernames to inject code into the Trivia module's leaderboard command. This exploit can be used to perform destructive actions and/or access sensitive information.
**Recommendations**
For versions prior to 3.3.11, update to version 3.3.11 to completely patch this issue.
As a temporary workaround, consider unloading the Trivia module with `unload trivia` to render this exploit not accessible.