Impact
Legcord versions 1.1.0 through 1.3.0 have a path‑traversal flaw in the theme IPC handlers. An attacker able to run arbitrary script in the Discord application—such as through an XSS vulnerability—can supply specially crafted theme identifiers to the themes.folder, themes.uninstall, and themes.install RPCs. This allows the attacker to write files, delete directories recursively, and launch local executables from outside the authorized themes folder, effectively gaining arbitrary code execution on the host machine.
Affected Systems
Legcord Legcord users running any version between 1.1.0 and 1.3.0 are affected. The vulnerability is tied to the IPC handlers that handle theme operations.
Risk and Exploitability
The CVSS score of 9.2 indicates a critical severity. Exploitation requires the attacker to have script execution capability within the Discord origin, likely via an XSS flaw. Because the exploit can execute arbitrary code, create or delete files on the system, and is not mitigated by any known service restrictions, the risk is very high. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the high CVSS and the local‑execution nature suggest it should be treated as a top‑priority issue.
OpenCVE Enrichment