CVE-2020-15147 is a Remote Code Execution (RCE) vulnerability affecting Red Discord Bot versions prior to 3.3.12 and 3.4, specifically within its Streams module. This high-severity vulnerability (CVSS 8.5) allows authenticated Discord users to inject malicious code into the bot via specially crafted "going live" messages, leading to potential data compromise, system disruption, and unauthorized access. While there is no evidence of active exploitation, public exploit code, or significant community discussion, immediate patching to versions 3.3.12 or 3.4 is strongly recommended to mitigate this risk. As a temporary workaround, unloading the Streams module can prevent exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3.11CPE matchmatch criteria | cpe:2.3:a:cogboard:red_discord_bot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.