py-cord is a an API wrapper for Discord written in Python. Bots using py-cord version 2.0.0 are vulnerable to remote shutdown if they are added to the server with the application.commands
scope without the bot
scope. Currently, it appears that all public bots that use slash commands are affected.
This issue has been patched in version 2.0.1.
There are currently no recommended workarounds - please upgrade to a patched version.
https://github.com/Pycord-Development/pycord/pull/1568
If you have any questions or comments about this advisory: * Open an issue in our GitHub * Email us at support@pycord.dev
{ "nvd_published_at": "2022-08-18T15:15:00Z", "cwe_ids": [ "CWE-284" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-08-18T14:18:37Z" }