Impact
The vulnerability allows a regular user to create a support ticket with a reason that contains @everyone, @here, user, or role mentions. The bot posts the attacker‑controlled reason in the new ticket channel without suppressing the mentions, letting an attacker trigger spam notifications to staff or all channel users if the bot has the required permissions. This can lead to disruptive flooding, potential phishing, and a denial of service against the moderation workflow.
Affected Systems
Duck‑organization Quest Bot for Discord, any release prior to version 1.0.3. Users running these versions are vulnerable when the bot can post ticket reasons that contain mentions.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attacker needs only the normal ability to invoke the ticket command and a bot that has mention permissions; the exploit requires no additional privileges or complex setup, making it readily actionable for a malicious user.
OpenCVE Enrichment