
Security-research lab: CVE-2026-47172 (workflow_run pwn request in deploy.yaml) — flattened snapshot of duck-organization/questbot at 1903b2f
Automated research artifact — not the upstream project.
This repository is a disposable lab built by an automated harness for a master's thesis at Université Laval on reproducing published GitHub Actions workflow vulnerabilities. It is a verbatim snapshot of
duck-organization/questbotat commit1903b2f9677e7104c5f64dd5bd1a72db130f143e(2026-05-17), redistributed under that project's own licence, whose file is included unchanged in this snapshot.The upstream project is not involved, is never targeted, and the vulnerability studied here is already public. Every secret and variable in this repository is a randomly generated dummy value — no real credential is present. Action references and runner images are pinned to what they resolved to on 2026-05-17; see
pinning.mdin the harness output for every change made to the snapshot.Questions or objections: [email protected]
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support!
Quest Bot is capable of:
Quest Bot is worked on by Duck Organization but we are opensource! Anyone can contribute!
Feel free to open a pull request! Just make sure to follow the guidelines at CONTRIBUTING.md.
.env file based on .env.example and fill in the required values.pnpm installpnpm devThis project is licensed under the Affero GNU General Public License v3.0 (AGPL-3.0). See LICENSE for more details.
If you have any questions or suggestions, feel free to reach out to us on our Discord server or send us an email at [email protected].