CVE-2024-39905: Cog-Creators Red-Discordbot
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Red is a fully modular Discord bot. Due to a bug in Red's Core API, 3rd-party cogs using the `@commands.can_manage_channel()` command permission check without additional permission controls may authorize a user to run a command even when that user doesn't have permissions to manage a channel. None of the core commands or core cogs are affected. The maintainers of the project are not aware of any _public_ 3rd-party cog utilizing this API at the time of writing this advisory. The problem was patched and released in version 3.5.10.
Affected products
- Cog-Creators Red-Discordbot: from 3.5.0, before 3.5.10 (fixed in 3.5.10)
- Cogboard Red Discord Bot: from 3.5.0, before 3.5.10 (fixed in 3.5.10)
Published 2024-07-11. Last modified 2026-06-17.