VYPR
Critical severity9.8NVD Advisory· Published Aug 20, 2024· Updated Jun 17, 2026

CVE-2024-43404

CVE-2024-43404

Description

MEGABOT is a fully customized Discord bot for learning and fun. The /math command and functionality of MEGABOT versions < 1.5.0 contains a remote code execution vulnerability due to a Python eval(). The vulnerability allows an attacker to inject Python code into the expression parameter when using /math in any Discord channel. This vulnerability impacts any discord guild utilizing MEGABOT. This vulnerability was fixed in release version 1.5.0.

Affected products

3
  • Nicpwns/Megabotllm-fuzzy2 versions
    <1.5.0+ 1 more
    • (no CPE)range: <1.5.0
    • (no CPE)range: < 1.5.0
  • cpe:2.3:a:megacord:megabot:*:*:*:*:*:*:*:*
    Range: <1.5.0

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.