Skip to content

Remote Code Execution in Act module

High
Zephyrkul published GHSA-rm7m-j4xp-rv2p Sep 15, 2020

Package

act (Red Discord Bot)

Affected versions

< 6b9f3b862e1f0a5429c62f3090f814e53a242347

Patched versions

6b9f3b862e1f0a5429c62f3090f814e53a242347

Description

Impact

An RCE exploit has been discovered in the Act module. With this exploit, Discord users can use specially crafted messages to perform destructive actions and/or access sensitive information.

Patches

This exploit has been patched in commit 6b9f3b86

Workarounds

Unloading the Act module with unload act can render this exploit inaccessible.

References

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2020-15172

Weaknesses

No CWEs