Core Bot Sensitive Data Exposure Vulnerability in Discord Webhook Handling

Vulnerability

A vulnerability exists in Core Bot, an open-source Discord bot for Maple Hospital servers, allowing for the unintentional leakage of sensitive API keys (SUPABASE_API_KEY, TOKEN) through error handling, summaries, and webhooks. Prior to the patch in commit dffe050, the bot's configuration summaries could expose these secrets by failing to properly redact them in summary embeds or logs. This exposure could potentially grant attackers control over the bot or its associated database.

Impact

The vulnerability could lead to the unauthorized disclosure of API keys, allowing attackers to gain control over the bot and its database.

Remediation

Users are advised to update to the latest version of Core Bot, where this vulnerability has been patched. The update can be obtained from the Core Bot GitHub repository.

Added: Nov 26, 2025, 12:18 AM
Updated: Nov 26, 2025, 12:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.9
remediation
0.0
relevance
1.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.