GSSA-2026-04-RHBD5TGITLAB-GSSA-2026-04-RHBD5TApril 25, 20267.1 High
Discord bot /config and /setchannel commands lacked authorization in cobc-events
The `/config` and `/setchannel` slash commands in cobc-events <1.0.1 had no permission check, letting any guild member toggle logging features or reroute strike/event/LoA log channels.
Affected (1)
- gelhaus-solutionscobc-events
- ≥ 0.0.0Fixed in 1.0.1
Mitigations
Workarounds
- Restrict the bot to a private staff-only Discord server until upgrade.
- Remove the `/config` and `/setchannel` command registrations via the Discord developer portal.
Solutions
- Upgrade cobc-events to 1.0.1 or later.
- Audit `DiscordServerConfig` rows for unexpected channel routing.
Exploits
- Any member in a guild where the bot is installed runs `/setchannel type:strikeChannelId channel:#general`. Future strike notifications are now broadcast publicly instead of in the moderator channel.
Overview
The /config and /setchannel slash commands in cobc-events <1.0.1 had no permission check, letting any guild member toggle logging features or reroute strike/event/LoA log channels.
Severity
CVSS v3
7.1 High
7.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- Low
- Integrity
- High
- Availability
- Low
Weaknesses (3)
References (2)
- Patch in src/bot/index.js (Patch)
- discord.js permissions (Technical description)
Credits (5)
- Enno GelhausFinder · egelhaus@ennogelhaus.de
- Enno GelhausAnalyst · egelhaus@ennogelhaus.de
- Enno GelhausRemediation developer · egelhaus@ennogelhaus.de
- Enno GelhausRemediation reviewer · egelhaus@ennogelhaus.de
- Claude (Anthropic) — automated audit assistantTool · https://claude.com
Context
Impacts
Unauthorized configuration of Discord server logging by non-staff members
CAPEC-122Suppression of moderator audit logs (integrity loss)
Timeline
- 04/25/2026 00:00
Internal security audit started
- 04/25/2026 06:00
Vulnerability identified during audit
- 04/25/2026 12:00
Patch developed and merged to main
- 04/25/2026 14:00
cobc-events 1.0.1 released
- 04/25/2026 15:00
Advisory published