CVE-2025-53943: DEATH1CLOWN Voidbot Open-Source

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

VoidBot Open-Source is a customizable Discord bot. VoidBot Open-Source versions 0.0.1 through 0.8.1 contain a vulnerability in the command handler where permission checks are not properly enforced for certain administrative commands. This allows users without the required roles or privileges to execute sensitive commands such as `ban`, `kick`, or `shutdown`, potentially disrupting server operations. Version 1.0.0 fixes the issue.

Affected products

  • DEATH1CLOWN Voidbot Open-Source: from 0.0.1, before 1.0.0 (fixed in 1.0.0)

Published 2025-07-16. Last modified 2026-06-17.