A vulnerability was found in duck-organization questbot up to 1.1.7. It has been declared as problematic. This issue affects some unknown processing. The manipulation results in allocation of resources.

This vulnerability is reported as CVE-2026-49347. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.