PT-2026-48861 · Quest Bot · Quest-Bot

Published

2026-06-12

·

Updated

2026-06-12

·

CVE-2026-48485

CVSS v4.0

2.1

Low

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Quest Bot versions prior to 1.1.6
Description Quest Bot suppresses mentions during several administrative actions, such as creating, unbanning, unwarning, kicking, muting, and unmuting. However, warning reasons stored in the system are printed by the /warns endpoint without mention suppression. This allows a moderator to include @everyone or @here in a warning reason, which can subsequently trigger a mass ping when the bot outputs that reason, provided the bot has the necessary permissions.
Recommendations Update to version 1.1.6.

Exploit

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2026-48485

Affected Products

Quest-Bot