PT-2026-48861 · Quest Bot · Quest-Bot
Published
2026-06-12
·
Updated
2026-06-12
·
CVE-2026-48485
CVSS v4.0
2.1
Low
| Vector | AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Quest Bot versions prior to 1.1.6
Description
Quest Bot suppresses mentions during several administrative actions, such as creating, unbanning, unwarning, kicking, muting, and unmuting. However, warning reasons stored in the system are printed by the
/warns endpoint without mention suppression. This allows a moderator to include @everyone or @here in a warning reason, which can subsequently trigger a mass ping when the bot outputs that reason, provided the bot has the necessary permissions.Recommendations
Update to version 1.1.6.
Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quest-Bot