CVE-2020-15140
Python vulnerability analysis and mitigation

Overview

In Red Discord Bot versions 3.3.10 and earlier, a Remote Code Execution (RCE) vulnerability was discovered in the Trivia module, identified as CVE-2020-15140. The vulnerability was discovered and disclosed in August 2020, affecting the Trivia module's leaderboard command functionality. The vulnerability allowed Discord users with specifically crafted usernames to inject malicious code into the system (GitHub Advisory).

Technical details

The vulnerability existed in the Trivia module's leaderboard command where user input from Discord usernames was not properly sanitized. The issue stemmed from an unnecessary .format call in the code that allowed for Python string formatting injection. This vulnerability was fixed in version 3.3.11 by removing the problematic format call (GitHub Commit).

Impact

The exploitation of this vulnerability could allow attackers to perform destructive actions and potentially access sensitive information through the injected code execution. The severity of this vulnerability was rated as High due to the potential for unauthorized code execution and system compromise (GitHub Advisory).

Exploitability

The vulnerability could be exploited by Discord users who could craft specific usernames that would trigger code injection when the Trivia module's leaderboard command was executed. The exploit was discovered and reported by security researcher douglascdev (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in Red Discord Bot version 3.3.11. As a temporary workaround, users of affected versions could unload the Trivia module using the command 'unload trivia' to prevent exploitation. However, updating to version 3.3.11 or later was strongly recommended for complete remediation (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61539CRITICAL10
  • Python logoPython
  • xinference
NoYesAug 21, 2026
CVE-2026-49360HIGH7.8
  • Python logoPython
  • recce
NoYesAug 21, 2026
CVE-2026-68508HIGH7.8
  • Python logoPython
  • hydra-core
NoYesAug 21, 2026
CVE-2026-43980MEDIUM6.3
  • Python logoPython
  • malla
NoNoAug 21, 2026
CVE-2026-55468MEDIUM4.3
  • Python logoPython
  • wagtail
NoYesAug 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management