{"id":"GHSA-93fv-4pm9-xp28","aliases":[],"url":"https://o3.security/vulnerability/GHSA-93fv-4pm9-xp28","summary":"JDA (Java Discord API) downloads external URLs when updating message components","details":"### Impact\n\nAnyone using untrusted message components may be affected. On versions >=6.0.0,<6.1.3 of JDA, the requester will attempt to download external media URLs from components if they are used in an update or send request.\n\nIf you are used `Message#getComponents` or similar to get a list of components and then send those components with `sendMessageComponents` or other methods, you might unintentionally download media from an external URL in the resolved media of a `Thumbnail`, `FileDisplay`, or `MediaGallery`.\n\n### Patches\n\nThis bug has been fixed in 6.1.3, and we recommend updating.\n\n### Workarounds\n\nAvoid sending components from untrusted messages or update to version 6.1.3.","published":"2025-12-09T17:23:54Z","modified":"2025-12-09T17:36:14.284022Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"net.dv8tion:JDA","fixedVersion":"6.1.3"}],"fix":{"url":"https://github.com/discord-jda/JDA/commit/bb6d2ce5cf514429327c257f5c6fa95a137e3ab6","label":"discord-jda/JDA@bb6d2ce"},"references":[{"type":"WEB","url":"https://github.com/discord-jda/JDA/security/advisories/GHSA-93fv-4pm9-xp28"},{"type":"WEB","url":"https://github.com/discord-jda/JDA/commit/bb6d2ce5cf514429327c257f5c6fa95a137e3ab6"},{"type":"PACKAGE","url":"https://github.com/discord-jda/JDA"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-12-09T17:36:14.284022Z"}}