Impact
The flaw allows a moderator to embed @everyone or @here in the reason parameter of the /unban and /unwarn moderation commands. The bot echoes the supplied reason back in a public message without sanitizing or disabling mentions, so the text is rendered as a mass ping. This abuse can overwhelm users with unwanted notifications, creating a disruption that resembles a lightweight denial‑of‑service. The underlying weakness is a text‑handling vulnerability (CWE‑116).
Affected Systems
Duck Organization Quest Bot, any deployment running a version earlier than 1.0.5. The issue was addressed in release v1.0.5, which implements mention suppression for these commands.
Risk and Exploitability
The CVSS score of 2.3 classifies the vulnerability as low severity. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog. Exploitation requires only that an attacker possess moderator privileges on the Discord server; no additional conditions or remote code execution are needed. The risk is limited to mass‑mentioning annoyance rather than compromise of the bot or server.
OpenCVE Enrichment