{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3alegcordlegcord1.1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:legcord:legcord:1.1.0:*:*:*:*:*:*:*","cpe:2.3:a:legcord:legcord:1.3.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-105293"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Legcord (1.1.0 through 1.3.0)","Legcord (1.1.0-1.3.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal","code-execution"],"_cs_type":"advisory","_cs_vendors":["Legcord"],"content_html":"\u003cp\u003eLegcord versions 1.1.0 through 1.3.0 are susceptible to a path traversal vulnerability within their theme inter-process communication (IPC) handlers. The flaw exists because the application fails to adequately validate 'theme id' parameters before processing them. An attacker who has achieved script execution within the Discord origin, perhaps through a secondary XSS attack, can leverage the 'themes.folder', 'themes.uninstall', and 'themes.install' IPC handlers to break out of the intended themes directory. This access grants the ability to perform unauthorized file operations, including recursive directory deletion and arbitrary file writes, as well as the execution of local binaries on the host system. This vulnerability poses a significant risk to host integrity for users of the affected Legcord versions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-105293 allows for arbitrary code execution, unauthorized data destruction, and unauthorized file system modification on the host system where Legcord is installed. By escaping the application sandbox, an attacker can impact the entire user profile, potentially leading to persistent malware installation or data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Legcord to a version beyond 1.3.0 immediately once a patch is released by the maintainers.\u003c/li\u003e\n\u003cli\u003eMonitor for anomalous process creation events originating from the Legcord process tree, particularly those involving non-standard child processes.\u003c/li\u003e\n\u003cli\u003eImplement endpoint controls to restrict the execution of binaries located within or spawned from user-writable application directories associated with Legcord.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T01:43:47Z","date_published":"2026-10-05T01:43:38Z","id":"https://feed.craftedsignal.io/briefs/2026-10-legcord-path-traversal/","summary":"Legcord versions 1.1.0 through 1.3.0 contain a path traversal vulnerability in IPC handlers that allows arbitrary file system manipulation and command execution when triggered via cross-origin script injection.","title":"Path Traversal Vulnerability in Legcord Theme IPC Handlers","url":"https://feed.craftedsignal.io/briefs/2026-10-legcord-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:legcord:legcord:1.1.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}