<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Legcord (1.1.0 Through 1.3.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/legcord-1.1.0-through-1.3.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 01:43:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/legcord-1.1.0-through-1.3.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal Vulnerability in Legcord Theme IPC Handlers</title><link>https://feed.craftedsignal.io/briefs/2026-10-legcord-path-traversal/</link><pubDate>Mon, 05 Oct 2026 01:43:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-legcord-path-traversal/</guid><description>Legcord versions 1.1.0 through 1.3.0 contain a path traversal vulnerability in IPC handlers that allows arbitrary file system manipulation and command execution when triggered via cross-origin script injection.</description><content:encoded><![CDATA[<p>Legcord versions 1.1.0 through 1.3.0 are susceptible to a path traversal vulnerability within their theme inter-process communication (IPC) handlers. The flaw exists because the application fails to adequately validate 'theme id' parameters before processing them. An attacker who has achieved script execution within the Discord origin, perhaps through a secondary XSS attack, can leverage the 'themes.folder', 'themes.uninstall', and 'themes.install' IPC handlers to break out of the intended themes directory. This access grants the ability to perform unauthorized file operations, including recursive directory deletion and arbitrary file writes, as well as the execution of local binaries on the host system. This vulnerability poses a significant risk to host integrity for users of the affected Legcord versions.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-105293 allows for arbitrary code execution, unauthorized data destruction, and unauthorized file system modification on the host system where Legcord is installed. By escaping the application sandbox, an attacker can impact the entire user profile, potentially leading to persistent malware installation or data exfiltration.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for detection engineering teams:</p>
<ul>
<li>Upgrade Legcord to a version beyond 1.3.0 immediately once a patch is released by the maintainers.</li>
<li>Monitor for anomalous process creation events originating from the Legcord process tree, particularly those involving non-standard child processes.</li>
<li>Implement endpoint controls to restrict the execution of binaries located within or spawned from user-writable application directories associated with Legcord.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>path-traversal</category><category>code-execution</category></item></channel></rss>