{"id":"CVE-2022-36024","aliases":["GHSA-qmhj-m29v-gvmr","PYSEC-2022-43146"],"url":"https://o3.security/vulnerability/CVE-2022-36024","summary":"Bots using py-cord as discord api wrapper are vulnerable to shutdowns through remote code execution","details":"py-cord is a an API wrapper for Discord written in Python. Bots creating using py-cord version 2.0.0 are vulnerable to remote shutdown if they are added to the server with the `application.commands` scope without the `bot` scope. Currently, it appears that all public bots that use slash commands are affected. This issue has been patched in version 2.0.1. There are currently no recommended workarounds - please upgrade to a patched version.","published":"2022-08-18T14:45:17Z","modified":"2026-08-12T03:51:28.573118622Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.0078,"percentile":0.5353,"asOf":"2026-09-04"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"py-cord","fixedVersion":"2.0.1"}],"fix":{"url":"https://github.com/Pycord-Development/pycord/pull/1568","label":"Pycord-Development/pycord#1568"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/36xxx/CVE-2022-36024.json"},{"type":"ADVISORY","url":"https://github.com/Pycord-Development/pycord/security/advisories/GHSA-qmhj-m29v-gvmr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36024"},{"type":"FIX","url":"https://github.com/Pycord-Development/pycord/pull/1568"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:28.573118622Z"}}