CVE-2026-105293: Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers
Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outside the themes directory.
Affected Software
Event History
Frequently Asked Questions
What conditions are required for exploitation?
An attacker must be able to run script in the Discord page’s origin, such as by exploiting an XSS issue. No privileges or user interaction are required once that script execution is available.
What can an attacker do through the affected IPC handlers?
By supplying unvalidated theme IDs to themes.folder, themes.uninstall, or themes.install, attacker-controlled script can access paths outside the themes directory. The reported impacts include launching local executables, recursively deleting directories, and writing files outside that directory.
Which installations are affected?
Legcord versions 1.1.0 through 1.3.0 are affected. The provided information does not identify a fixed version or a configuration-based workaround.