CVE-2022-36024 Information

Description

A fork of discord.py py-cord is a modern easy to use feature-rich and async ready API wrapper for Discord written in Python. This issue allows users to be able to remotely shutdown the a bot running on py-cord via adding it to a discord server with the application.commands scope but not the bot scope - then executing a command in that server. Currently it appears that all public bots that use slash commands are affected. This issue has been patched in version 2.0.1. There are currently no recommended workarounds - please upgrade to a patched version.

Reference

https://github.com/Pycord-Development/pycord/security/advisories/GHSA-qmhj-m29v-gvmr https://github.com/Pycord-Development/pycord/pull/1568

Share on: