Impact
The bot echoes user‑controlled reason text in public moderation replies without disabling mention parsing, allowing an attacker to cause the bot to post @everyone or @here pings and flood the server. This flaw is a form of uncontrolled output of unencoded text (CWE‑116).
Affected Systems
Duck‑Organization Quest Bot versions prior to 1.0.4 are affected. The issue was fixed in v1.0.4, which suppresses mention parsing in moderation replies.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity; EPSS data is not available and the vulnerability is not in the CISA KEV catalog. Exploitation requires that an attacker can invoke a moderation command and that the bot possesses @everyone or @here permissions. Under those conditions, the risk is limited to injection of large‑volume notification pings.
OpenCVE Enrichment