Description
Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outside the themes directory.
Published: 2026-10-05
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: Remote code execution via local file manipulation
Action: Patch immediately
AI Analysis

Impact

Legcord versions 1.1.0 through 1.3.0 have a path‑traversal flaw in the theme IPC handlers. An attacker able to run arbitrary script in the Discord application—such as through an XSS vulnerability—can supply specially crafted theme identifiers to the themes.folder, themes.uninstall, and themes.install RPCs. This allows the attacker to write files, delete directories recursively, and launch local executables from outside the authorized themes folder, effectively gaining arbitrary code execution on the host machine.

Affected Systems

Legcord Legcord users running any version between 1.1.0 and 1.3.0 are affected. The vulnerability is tied to the IPC handlers that handle theme operations.

Risk and Exploitability

The CVSS score of 9.2 indicates a critical severity. Exploitation requires the attacker to have script execution capability within the Discord origin, likely via an XSS flaw. Because the exploit can execute arbitrary code, create or delete files on the system, and is not mitigated by any known service restrictions, the risk is very high. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the high CVSS and the local‑execution nature suggest it should be treated as a top‑priority issue.

Generated by OpenCVE AI on October 5, 2026 at 02:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Legcord to a version newer than 1.3.0 that fixes the path‑traversal logic.
  • If an update is not yet available, remove or disable the theme IPC handling feature or apply a local patch that validates theme identifiers against a whitelist.
  • Add a strict Content Security Policy to the Discord origin so that arbitrary script execution is prevented, reducing the prerequisite XSS attack that can trigger the flaw.

Generated by OpenCVE AI on October 5, 2026 at 02:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 01:00:00 +0000

Type Values Removed Values Added
Description Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outside the themes directory.
Title Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-05T00:44:18.687Z

Reserved: 2026-10-05T00:19:05.720Z

Link: CVE-2026-105293

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T01:16:28.780

Modified: 2026-10-05T01:16:28.780

Link: CVE-2026-105293

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T02:30:08Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')