Dev.to Security 🔐 Cybersecurity 👁 0

Legcord (Discord Client) — 2 CVEs: XSS in Discord Page Becomes RCE + Persistent Traffic Interception

If you use Legcord as your Discord client, a script running in the Discord page can break out of the Electron sandbox entirely. CVE-2026-105293 (CVSS 8.1) — Path Traversal to RCE Theme IPC handlers (themes.install, them

If you use Legcord as your Discord client, a script running in the Discord page can break out of the Electron sandbox entirely.

CVE-2026-105293 (CVSS 8.1) — Path Traversal to RCE
Theme IPC handlers (themes.install, themes.uninstall, themes.folder) accept identifiers without sanitizing ../ sequences. Discord-origin script passes a traversal payload → writes arbitrary files, deletes directories, or launches local executables outside the themes directory.

CVE-2026-105294 (CVSS 7.4) — Config Injection → Persistent MITM
window.legcord.settings.setConfig has no allowlist. Script sets additionalArguments to --proxy-server=attacker-host --ignore-certificate-errors. Persists to disk. Every subsequent Legcord launch routes all traffic through the attacker's proxy with TLS validation silently disabled.

Both require Discord-origin XSS first — not drive-by, but chain-dependent exploitation is realistic.

No confirmed fixed version as of publication. Upgrade past 1.3.0 and check your config for injected proxy switches.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.