CVE-2025-53943

VoidBot Open-Source is a customizable Discord bot. VoidBot Open-Source versions 0.0.1 through 0.8.1 contain a vulnerability in the command handler where permission checks are not properly enforced for certain administrative commands. This allows users without the required roles or privileges to execute sensitive commands such as `ban`, `kick`, or `shutdown`, potentially disrupting server operations. Version 1.0.0 fixes the issue.
CVSS

No CVSS.

Configurations

No configuration.

History

17 Jul 2025, 21:15

Type Values Removed Values Added
Summary
  • (es) VoidBot Open-Source es un bot de Discord personalizable. Las versiones 0.0.1 a 0.8.1 de VoidBot Open-Source contienen una vulnerabilidad en el controlador de comandos, donde las comprobaciones de permisos no se aplican correctamente para ciertos comandos administrativos. Esto permite que usuarios sin los roles o privilegios necesarios ejecuten comandos sensibles como "ban", "kick" o "shutdown", lo que podría interrumpir las operaciones del servidor. La versión 1.0.0 corrige el problema.

16 Jul 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-16 16:15

Updated : 2025-07-17 21:15


NVD link : CVE-2025-53943

Mitre link : CVE-2025-53943

CVE.ORG link : CVE-2025-53943


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization