CPE
Legcord versions 1.1.0 through 1.3.0 contain a path traversal vulnerability in IPC handlers that allows arbitrary file system manipulation and command execution when triggered via cross-origin script injection.