{"id":"GHSA-hm45-mgqm-gjm4","summary":"Remote Code Execution (RCE) Exploit on Cross Site Scripting (XSS) Vulnerability","details":"### Impact\nA RCE exploit has been discovered in the Red Discord Bot - Dashboard Webserver: this exploit allows Discord users with specially crafted Server names and Usernames/Nicknames to inject code into the webserver front-end code.  By abusing this exploit, it's possible to perform destructive actions and/or access sensitive information.\n\n### Patches\nThis high severity exploit has been fixed on version `0.1.7a`.\n\n### Workarounds\nThere are no workarounds, bot owners must upgrade their relevant packages (Dashboard module and Dashboard webserver) in order to patch this issue\n\n### References\n- 99d88b8\n- a6b9785\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [Cog-Creators/Red-Dashboard](https://github.com/Cog-Creators/Red-Dashboard/issues/new/choose)\n* Over on the official [Red Server](https://discord.gg/red) or at the Third Party Server [Toxic Layer](https://discord.gg/vQZTdB9)","aliases":["CVE-2020-26249","PYSEC-2020-98"],"modified":"2026-07-08T05:59:35.567384290Z","published":"2020-12-08T23:55:54Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-12-08T23:55:41Z","nvd_published_at":null,"cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/Cog-Creators/Red-Dashboard/security/advisories/GHSA-hm45-mgqm-gjm4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26249"},{"type":"WEB","url":"https://github.com/Cog-Creators/Red-Dashboard/commit/99d88b840674674166ce005b784ae8e31e955ab1"},{"type":"WEB","url":"https://github.com/Cog-Creators/Red-Dashboard/commit/a6b9785338003ec87fb75305e7d1cc2d40c7ab91"},{"type":"PACKAGE","url":"https://github.com/Cog-Creators/Red-Dashboard"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/red-dashboard/PYSEC-2020-98.yaml"},{"type":"WEB","url":"https://pypi.org/project/Red-Dashboard"}],"affected":[{"package":{"name":"red-dashboard","ecosystem":"PyPI","purl":"pkg:pypi/red-dashboard"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.7a"}]}],"versions":["0.1.1a0","0.1.2a0","0.1.3a0","0.1.4a0","0.1.5a0","0.1.6a0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/12/GHSA-hm45-mgqm-gjm4/GHSA-hm45-mgqm-gjm4.json","last_known_affected_version_range":"\u003c= 0.1.6a"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"}]}