Quest Bot: Ticket creation has no per-user open-ticket limit or cooldown
CVE-2026-49347
5.3MEDIUM
What is CVE-2026-49347?
Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly create new ticket channels. The latest release still creates a new database ticket and Discord channel for every completed ticket modal submission, without checking whether the same user already has an open ticket and without applying a cooldown. This issue has been patched in version 1.1.8.
Affected Version(s)
questbot < 1.1.8
