VoidBot Open-Source is a customizable Discord bot. VoidBot Open-Source versions 0.0.1 through 0.8.1 contain a vulnerability in the command handler where permission checks are not properly enforced for certain administrative commands. This allows users without the required roles or privileges to execute sensitive commands such as `ban`, `kick`, or `shutdown`, potentially disrupting server operations. Version 1.0.0 fixes the issue.
History

Fri, 18 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
Description VoidBot Open-Source is a customizable Discord bot. VoidBot Open-Source versions 0.0.1 through 0.8.1 contain a vulnerability in the command handler where permission checks are not properly enforced for certain administrative commands. This allows users without the required roles or privileges to execute sensitive commands such as `ban`, `kick`, or `shutdown`, potentially disrupting server operations. Version 1.0.0 fixes the issue.
Title VoidBot Open-Source Has Improper Permission Check That Allows Unauthorized Command Execution
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-16T16:07:52.120Z

Updated: 2025-07-18T14:32:27.175Z

Reserved: 2025-07-14T17:23:35.262Z

Link: CVE-2025-53943

cve-icon Vulnrichment

Updated: 2025-07-18T14:32:24.379Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-16T16:15:29.417

Modified: 2025-07-17T21:15:50.197

Link: CVE-2025-53943

cve-icon Redhat

No data.