Legcord (Discord Client) — 2 CVEs: XSS in Discord Page Becomes RCE + Persistent Traffic Interception
If you use Legcord as your Discord client, a script running in the Discord page can break out of the Electron sandbox entirely. CVE-2026-105293 (CVSS 8.1) — Path Traversal to RCE Theme IPC handlers (themes.install, them
If you use Legcord as your Discord client, a script running in the Discord page can break out of the Electron sandbox entirely.
CVE-2026-105293 (CVSS 8.1) — Path Traversal to RCE
Theme IPC handlers (themes.install, themes.uninstall, themes.folder) accept identifiers without sanitizing ../ sequences. Discord-origin script passes a traversal payload → writes arbitrary files, deletes directories, or launches local executables outside the themes directory.
CVE-2026-105294 (CVSS 7.4) — Config Injection → Persistent MITM
window.legcord.settings.setConfig has no allowlist. Script sets additionalArguments to --proxy-server=attacker-host --ignore-certificate-errors. Persists to disk. Every subsequent Legcord launch routes all traffic through the attacker's proxy with TLS validation silently disabled.
Both require Discord-origin XSS first — not drive-by, but chain-dependent exploitation is realistic.
No confirmed fixed version as of publication. Upgrade past 1.3.0 and check your config for injected proxy switches.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.