Bots using py-cord as Discord API wrapper are vulnerable to shutdowns through remote code execution
High severity
GitHub Reviewed
Published
Aug 16, 2022
in
Pycord-Development/pycord
•
Updated Nov 22, 2024
Description
Published to the GitHub Advisory Database
Aug 18, 2022
Reviewed
Aug 18, 2022
Published by the National Vulnerability Database
Aug 18, 2022
Last updated
Nov 22, 2024
Impact
py-cord is a an API wrapper for Discord written in Python. Bots using py-cord version 2.0.0 are vulnerable to remote shutdown if they are added to the server with the
application.commands
scope without thebot
scope. Currently, it appears that all public bots that use slash commands are affected.Patches
This issue has been patched in version 2.0.1.
Workarounds
There are currently no recommended workarounds - please upgrade to a patched version.
References
Pycord-Development/pycord#1568
For more information
If you have any questions or comments about this advisory:
References