Arbitrary Code Execution Vulnerability in Discord-Bot-Framework-Kernel by Discord
CVE-2025-26604

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
18 February 2025

What is CVE-2025-26604?

The Discord-Bot-Framework-Kernel allows the execution of arbitrary user-submitted code due to its design for modular extension management. This vulnerability enables attackers to execute malicious code, potentially compromising sensitive information such as the bot token. If an attacker exploits this, they can perform disruptive actions like DDoS attacks or create counterfeit bots that mimic legitimate counterparts, gaining full control over the bot's functions until the user intervenes. Users are strongly advised to upgrade to the latest version to mitigate this risk. For those unable to upgrade, limiting the bot's access through configuration settings is recommended.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Kernel commits before f0d9e70841a0e3170b88c4f8d562018ccd8e8b14

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.