{"id":"CVE-2021-29466","details":"Discord-Recon is a bot for the Discord chat service. In versions of Discord-Recon 0.0.3 and prior, a remote attacker is able to read local files from the server that can disclose important information. As a workaround, a bot maintainer can locate the file `app.py` and add `.replace('..', '')` into the `Path` variable inside of the `recon` function. The vulnerability is patched in version 0.0.4.","aliases":["GHSA-p2pw-8xwf-879g"],"modified":"2026-07-09T11:24:20.483862Z","published":"2021-04-22T01:15:07.740Z","references":[{"type":"ADVISORY","url":"https://github.com/DEMON1A/Discord-Recon/security/advisories/GHSA-p2pw-8xwf-879g"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/demon1a/discord-recon","events":[{"introduced":"0"},{"fixed":"16206b1e4e03433312917589bbb8b01ddf930fb1"}],"database_specific":{"cpe":"cpe:2.3:a:discord:discord-recon:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.0.4"}],"source":"CPE_RANGE"}}],"versions":["0,0.3","0.0.2","0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-29466.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}