diff --git a/app/imports/server/discord/sendWebhook.js b/app/imports/server/discord/sendWebhook.js index b88cae76..95eea823 100644 --- a/app/imports/server/discord/sendWebhook.js +++ b/app/imports/server/discord/sendWebhook.js @@ -4,6 +4,10 @@ export default function sendWebhook({webhookURL, message, options}){ let urlArray = webhookURL.split('/'); let token = urlArray.pop(); let id = urlArray.pop(); + + // prevent discord mention exploit + options.allowedMentions = { parse: [] }; + const hook = new Discord.WebhookClient(id, token); // Send a message using the webhook hook.send(message, options)