CVE-2026-47177 MEDIUM

CVE-2026-47177: Quest Bot: Ticket transcripts can disclose private ticket contents to a lower-visibility channel

Vendor Duck-Organization
Product quest-bot
Weakness CWE-200 · Info exposure
Published June 11, 2026
Last update June 11, 2026

CVSS base score

5.7/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a user who can configure bot settings can set the ticket transcript channel to a channel they can read. When tickets are closed, the bot exports the full ticket history and sends it to that configured transcript channel. This can expose private ticket messages to users who could not read the original ticket channel. This issue has been patched in version 1.0.4.

Key dates

02Disclosure timeline

June 11, 2026 CVE published
June 11, 2026 Record updated