CVE-2024-26136 - CVE House
Back to Database
Status published High CVE-2024-26136

kedi ElectronCord's Discord Token is public

Vulnerability Description

kedi ElectronCord is a bot management tool for Discord. Commit aaaeaf4e6c99893827b2eea4dd02f755e1e24041 exposes an account access token in the `config.json` file. Malicious actors could potentially exploit this vulnerability to gain unauthorized access to sensitive information or perform malicious actions on behalf of the repository owner. As of time of publication, it is unknown whether the owner of the repository has rotated the token or taken other mitigation steps aside from informing users of the situation.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-26136

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

ElectronCord
Vulnerable Versions:
= aaaeaf4e6c99893827b2eea4dd02f755e1e24041

Timeline

Official Publish: February 20th, 2024
Last Modified: August 28th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)