Arbitrary Code Execution Vulnerability in Discord-Bot-Framework-Kernel by Discord
CVE-2025-26604
What is CVE-2025-26604?
The Discord-Bot-Framework-Kernel allows the execution of arbitrary user-submitted code due to its design for modular extension management. This vulnerability enables attackers to execute malicious code, potentially compromising sensitive information such as the bot token. If an attacker exploits this, they can perform disruptive actions like DDoS attacks or create counterfeit bots that mimic legitimate counterparts, gaining full control over the bot's functions until the user intervenes. Users are strongly advised to upgrade to the latest version to mitigate this risk. For those unable to upgrade, limiting the bot's access through configuration settings is recommended.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Kernel commits before f0d9e70841a0e3170b88c4f8d562018ccd8e8b14
