Skip to content
Threat Feed
high advisory

Path Traversal Vulnerability in Legcord Theme IPC Handlers

Legcord versions 1.1.0 through 1.3.0 contain a path traversal vulnerability in IPC handlers that allows arbitrary file system manipulation and command execution when triggered via cross-origin script injection.

CVE search metadata

CVE search record: CVE-2026-105293. Severity: high. CVSS: 8.1. KEV: no. Product: Legcord (1.1.0 through 1.3.0), Legcord (1.1.0-1.3.0). Brief: Path Traversal Vulnerability in Legcord Theme IPC Handlers. Brief link: https://feed.craftedsignal.io/briefs/2026-10-legcord-path-traversal/

What's new

  • 1. added detection rule: Detect Legcord Launched with Suspicious Proxy Switches Oct 5, 01:43 via nvd

Legcord versions 1.1.0 through 1.3.0 are susceptible to a path traversal vulnerability within their theme inter-process communication (IPC) handlers. The flaw exists because the application fails to adequately validate 'theme id' parameters before processing them. An attacker who has achieved script execution within the Discord origin, perhaps through a secondary XSS attack, can leverage the 'themes.folder', 'themes.uninstall', and 'themes.install' IPC handlers to break out of the intended themes directory. This access grants the ability to perform unauthorized file operations, including recursive directory deletion and arbitrary file writes, as well as the execution of local binaries on the host system. This vulnerability poses a significant risk to host integrity for users of the affected Legcord versions.

Impact

Successful exploitation of CVE-2026-105293 allows for arbitrary code execution, unauthorized data destruction, and unauthorized file system modification on the host system where Legcord is installed. By escaping the application sandbox, an attacker can impact the entire user profile, potentially leading to persistent malware installation or data exfiltration.

Recommendation

Prioritized, concrete actions for detection engineering teams:

  • Upgrade Legcord to a version beyond 1.3.0 immediately once a patch is released by the maintainers.
  • Monitor for anomalous process creation events originating from the Legcord process tree, particularly those involving non-standard child processes.
  • Implement endpoint controls to restrict the execution of binaries located within or spawned from user-writable application directories associated with Legcord.

Immediate actions

Upgrade Legcord to the latest version to mitigate CVE-2026-105293.

IT Operations 72h

Mitigations

Upgrade to version 1.3.1 or higher once available.

immediate IT Operations

CVE-2026-105293

Detection coverage 1

Detect Legcord Launched with Suspicious Proxy Switches

high

Detects the execution of Legcord with command-line arguments that force traffic through an external proxy, potentially indicating exploitation of CVE-2026-105294.

sigma tactics: command_and_control techniques: T1071.001 sources: process_creation

Detection queries are available on the platform. Get full rules →