Impact
Legcord 1.1.0 through 1.3.0 contains a configuration injection flaw that allows a script running in the Discord web page to write any configuration key via the window.legcord settings.setConfig bridge. When a user is exposed to a Discord XSS, an attacker can set the *additionalArguments* key to persistently add command‑line switches such as ‑‑proxy‑server and ‑‑ignore‑certificate‑errors. The resulting client traffic is routed through an attacker‑controlled proxy, enabling traffic interception, tampering, or further code execution against the user.
Affected Systems
Any installation of Legcord version 1.1.0 through 1.3.0, regardless of operating system, is affected. The vulnerability operates through the settings.setConfig API exposed by the Legcord client and does not depend on a specific platform or architecture.
Risk and Exploitability
The flaw has a CVSS score of 9.1, indicating a high level of severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, so the current probability of active exploitation is unknown. Attack requires an active XSS vector within the Discord web page; once that condition is met, the configuration injection can be performed with minimal effort and has the potential to persistently alter client behavior, effectively allowing the attacker to control network traffic and possibly execute arbitrary code.
OpenCVE Enrichment