Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-26604— Possibility to retrieve bot token by malicious module developers in Discord-Bot-Framework-Kernel

CVSS 8.3 · High EPSS 0.11% · P29
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-26604

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Possibility to retrieve bot token by malicious module developers in Discord-Bot-Framework-Kernel
Source: NVD (National Vulnerability Database)
Vulnerability Description
Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension management and secure execution. Because of the nature of arbitrary user-submited code execution, this allows user to execute potentially malicious code to perform damage or extract sensitive information. By loading the module containing the following code and run the command, the bot token can be extracted. Then the attacker can load a blocking module to sabotage the bot (DDoS attack) and the token can be used to make the fake bot act as the real one. If the bot has very high privilege, the attacker basically has full control before the user kicks the bot. Any Discord user that hosts Discord-Bot-Framework-Kernel before commit f0d9e70841a0e3170b88c4f8d562018ccd8e8b14 is affected. Users are advised to upgrade. Users unable to upgrade may attempt to limit their discord bot's access via configuration options.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
信息暴露
Source: NVD (National Vulnerability Database)
Vulnerability Title
Discord Bot Framework Kernel 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Discord Bot Framework Kernel是Discord Agora开源的一个 Discord Bot 框架内核。 Discord Bot Framework Kernel存在信息泄露漏洞,该漏洞源于未正确处理用户提交的代码。攻击者利用该漏洞可以提取敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Discord-AgoraKernel commits before f0d9e70841a0e3170b88c4f8d562018ccd8e8b14 -

II. Public POCs for CVE-2025-26604

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-26604

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-26604

No comments yet


Leave a comment