CVE-2026-105294: Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig
Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches, routing all client traffic through an interception proxy.
Affected Software
Event History
Frequently Asked Questions
What must an attacker achieve to exploit this issue?
The attacker needs script execution in the Discord page, such as through a Discord XSS. That script can invoke the window.legcord settings.setConfig bridge to write configuration keys.
What is the practical impact after exploitation?
An attacker can persistently add the Chromium switches --proxy-server and --ignore-certificate-errors through the additionalArguments configuration. This can route all client traffic through an interception proxy while disabling certificate-error checks.
Which installations are affected?
Legcord versions 1.1.0 through 1.3.0 are identified as affected. The provided information does not state whether any particular default configuration prevents exposure.